IP Library › Granted Patent US 12,506,686
Granted Patent B2
US 12,506,686 · App. 18/427,447 · Granted Dec 23, 2025

Symmetric routing in virtualized networks

Inventors: Chirag Wighe (Milpitas, CA); Samrat Ganguly (Fremont, CA)
Assignee: Apple Inc.
H04L45/586H04L12/4641H04L63/0254H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,686
App. No.
18/427,447
Granted
Dec 23, 2025
Kind
B2
Abstract

Embodiments disclosed herein relate to source-based symmetric routing of network traffic in virtual networks. In particular, a source of network traffic in the virtual network is equipped with a routing table that causes the source of the network traffic to route the network traffic symmetrically across zones of the virtual network.

Claims (36)

1 . A tangible, non-transitory, computer-readable medium, comprising instructions that, when executed by processing circuitry, are configured to cause the processing circuitry to:

generate a routing table comprising one or more table entries, wherein each of the one or more table entries comprise a first zone, a second zone, and a firewall assignment;

receive an indication of an amount of inner-zone network traffic, an amount of cross-zone network traffic, and an amount of external network traffic associated with each of the first zone and the second zone; and

adjust the one or more table entries based on the amount of inner-zone network traffic, the amount of cross-zone network traffic, and the amount of external network traffic.

2 . The tangible, non-transitory, computer-readable medium of claim 1 , wherein the instructions are configured to cause the processing circuitry to generate an updated routing table based on the adjusted one or more table entries and provide the updated routing table to a plurality of network traffic sources.

3 . The tangible, non-transitory, computer-readable medium of claim 1 , wherein the instructions are configured to cause the processing circuitry to determine that a firewall associated with the firewall assignment is underperforming or over-utilized.

4 . The tangible, non-transitory, computer-readable medium of claim 3 , wherein the instructions are configured to cause the processing circuitry to modify the firewall assignment for the first zone and the second zone based on determining that the firewall associated with the firewall assignment is underperforming or over-utilized.

5 . The tangible, non-transitory, computer-readable medium of claim 4 , wherein the instructions are configured to cause the processing circuitry to adjust the one or more table entries based on modifying the firewall assignment.

6 . The tangible, non-transitory, computer-readable medium of claim 5 , wherein the instructions are configured to cause the processing circuitry to provide session data associated with modifying the firewall assignment.

7 . The tangible, non-transitory, computer-readable medium of claim 1 , wherein the amount of inner-zone network traffic, the amount of cross-zone network traffic, and the amount of external network traffic comprises the amount of inner-zone network traffic, the amount of cross-zone network traffic, and the amount of external network traffic received from the first zone and the second zone, the amount of inner-zone network traffic, the amount of cross-zone network traffic, and the amount of external network traffic sent from the first zone and the second zone, or both.

8 . The tangible, non-transitory, computer-readable medium of claim 1 , wherein the instructions are configured to cause the processing circuitry to determine network traffic between the first zone and the second zone.

9 . The tangible, non-transitory, computer-readable medium of claim 8 , wherein the instructions are configured to cause the processing circuitry to delay adjusting the one or more table entries based on the network traffic.

10 . The tangible, non-transitory, computer-readable medium of claim 1 , wherein the instructions are configured to cause the processing circuitry to execute a periodic poll to determine whether an update for the routing table is available.

11 . The tangible, non-transitory, computer-readable medium of claim 1 , wherein the instructions are configured to cause the processing circuitry to adjust the one or more table entries based on comparing the amount of inner-zone network traffic, the amount of cross-zone network traffic, or the amount of external network traffic to a performance metric.

12 . The tangible, non-transitory, computer-readable medium of claim 11 , wherein the performance metric is associated with an operational statistic.

13 . The tangible, non-transitory, computer-readable medium of claim 12 , wherein the operational statistic comprises a firewall latency rate of a firewall associated with the firewall assignment.

14 . A method comprising:

generating a routing table comprising one or more table entries, wherein each of the one or more table entries comprise a first zone, a second zone, and a firewall assignment;

receiving an indication of an amount of inner-zone network traffic, an amount of cross-zone network traffic, and an amount of external network traffic associated with each of the first zone and the second zone;

adjusting the one or more table entries based on the amount of inner-zone network traffic, the amount of cross-zone network traffic, and the amount of external network traffic;

generating an updated routing table based on the adjusted one or more table entries; and

providing the updated routing table to a virtual private cloud.

15 . The method of claim 14 , comprising determining a firewall associated with the firewall assignment is underperforming or over-utilized.

16 . The method of claim 15 , comprising modifying the firewall assignment based on determining that the firewall associated with the firewall assignment is underperforming or over-utilized.

17 . The method of claim 16 , comprising adjusting the one or more table entries based on modifying the firewall assignment.

18 . The method of claim 14 , comprising:

determining network traffic between the first zone and the second zone; and

delaying adjusting the one or more table entries based on the network traffic.

19 . A virtual network system, comprising:

a plurality of zones; and

a computer system configured to:

generate a routing table comprising one or more table entries, wherein each of the one or more table entries comprise a first zone of the plurality of zones, a second zone of the plurality of zones, and a firewall assignment, and wherein a first set of entries of the one or more table entries is associated with inner-zone traffic, a second set of entries of the one or more table entries is associated with cross-zone traffic, and a third set of entries of the one or more table entries is associated with external network traffic;

receive zone metrics associated with each of the first zone and the second zone;

adjust the one or more table entries based on the zone metrics; and

generate an updated routing table based on the adjusted one or more table entries.

20 . The virtual network system of claim 19 , wherein the virtual network system comprises a plurality of virtual private clouds, and wherein the computer system is configured to provide the updated routing table to the plurality of virtual private clouds.

Continuity (2)
Continuation 17484871 · Sep 24, 2021
Related Publication 20240243999A1 · Jul 18, 2024
References Cited (14)
US 8139572B1 · Distler · 2012 [cited by examiner]
US 8634428B2 · Le Pennec · 2014 [cited by examiner]
US 8789135B1 · Pani · 2014 [cited by examiner]
US 10313241B2 · Bethers · 2019 [cited by examiner]
US 11849383B2 · Avva · 2023 [cited by examiner]
US 20140278623A1 · Martinez · 2014 [cited by examiner]
US 20140380125A1 · Calder · 2014 [cited by examiner]
US 20160285826A1 · Itskin · 2016 [cited by examiner]
US 20160285913A1 · Itskin · 2016 [cited by examiner]
US 20170126787A1 · Martinez · 2017 [cited by examiner]
US 20200177539A1 · Mittal · 2020 [cited by examiner]
Davies, Justin; “Introducing AWS Gateway Load Balancer: Supported architecture patterns”; https://aws.amazon.com/blogs/networking-and-content-delivery/introducing-aws-gateway-load-balancer-supported-architecture-pattern… [cited by examiner]
Davies, Justin; “Introducing AWS Gateway Load Balancer: Supported architecture patterns”; https://aws.amazon.com/blogs/networking-and-content-delivery/introducing-aws-gateway-load-balancer-supported-architecture-pattern… [cited by applicant]
International Search Report & Written Opinion for PCT Application No. PCT/US2022029873 dated Aug. 19, 2022; 17 pgs. [cited by applicant]