IP Library Granted Patent US 12,641,021
Granted Patent B2
US 12,641,021 · App. 17/745,502 · Granted May 26, 2026

Systems and methods for network packet translation

Inventors: Sebastiano Borgione (Bellevue, WA); John S G Peach (Berkshire, GB)
Assignee: Arista Networks, Inc.
H04L45/745H04L12/18H04L61/2557H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,021
App. No.
17/745,502
Granted
May 26, 2026
Kind
B2
Abstract

A method for modifying packet data of a packet in a network device, where the method includes receiving, at an ingress pipeline of the network device, the packet, performing a lookup, in a packet translation ruleset, to compare the packet data to rule criteria of a rule in the packet translation ruleset, making a first determination that at least a portion of the packet data matches the rule criteria, and based on the first determination, adding a packet translation tag to the packet, where the packet translation tag includes a rule action, copying the packet translation tag and a portion of the packet to obtain a copied packet, modifying the copied packet as described in the rule action to obtain a modified copied packet, and forwarding the modified copied packet to an egress pipeline.

Claims (74)

1 . A method for modifying packet data of a packet in a network device, wherein the method comprises:

receiving, at an ingress pipeline of the network device, the packet;

performing a lookup, in a packet translation ruleset, to compare the packet data to rule criteria of a rule in the packet translation ruleset, the rule associated with a rule action;

making a first determination that at least a first portion of the packet data matches the rule criteria; and

based on the first determination:

adding a packet translation tag to the packet, wherein the packet translation tag added to the packet comprises the rule action associated with the matching rule associated with the matching rule criteria, wherein the rule action describes a modification to perform on the packet;

creating a copy of the packet by copying the packet translation tag comprising the rule action and at least a second portion of the packet data to obtain the copied packet;

modifying the copied packet according to the modification as described in the rule action included in the packet translation tag of the copied packet to obtain a modified copied packet; and

forwarding the modified copied packet to an egress pipeline.

2 . The method of claim 1 , wherein modifying the copied packet comprises:

changing a destination IP address of the packet to a modified destination IP address.

3 . The method of claim 2 , wherein modifying the copied packet further comprises:

changing a source IP address of the packet to a modified source IP address.

4 . The method of claim 3 , wherein the source IP address and the destination IP address belong to a same first subnet.

5 . The method of claim 4 , wherein the modified source IP address and the modified destination IP address do not belong to a same second subnet.

6 . The method of claim 1 , wherein after adding the packet translation tag to the packet and before copying the packet, the method further comprises:

placing the packet in a packet translation queue.

7 . The method of claim 6 , wherein after placing the packet in the packet translation queue, the method further comprises:

identifying the packet in the packet translation queue.

8 . The method of claim 1 , wherein the method further comprises:

decrementing a counter of the packet translation tag; and

making a second determination, that the counter indicates a second copy of the packet needs to be sent.

9 . The method of claim 8 , wherein, based on the second determination, the method further comprises:

copying the packet translation tag and the second portion of the packet data to obtain a second copied packet, wherein the packet translation tag comprises a second rule action;

modifying the second copied packet as described in the second rule action to obtain a second modified copied packet; and

forwarding the second modified copied packet to the egress pipeline.

10 . The method of claim 9 , wherein the rule action specifies a first modified destination IP address, wherein the second rule action specifies a second modified destination IP address, wherein the first modified destination IP address and the second modified destination IP address are different.

11 . The method of claim 9 , wherein the method further comprises:

wherein after forwarding the modified copied packet to the egress pipeline:

the modified copied packet is routed through a first intermediate network, and

wherein after forwarding the second modified copied packet to the egress pipeline:

the second modified copied packet is routed through a second intermediate network.

12 . The method of claim 11 , wherein modifying the copied packet as described in the rule action, comprises:

changing a protocol of the copied packet from unicast to multicast.

13 . The method of claim 9 , wherein a protocol of the packet is unicast.

14 . The method of claim 1 , wherein the method further comprises:

receiving, at the ingress pipeline of the network device, a second packet;

performing a second lookup, in the packet translation ruleset, to compare second packet data of the second packet to second rule criteria of the rule in the packet translation ruleset;

making a second determination that at least a first portion of the second packet data matches the rule criteria; and

based on the second determination:

adding a second packet translation tag to the second packet, wherein the second packet translation tag comprises a second rule action associated with the rule associated with the matching rule criteria;

copying the second packet translation tag and at least a second portion of the second packet data to obtain a second copied packet;

modifying the second copied packet as described in the second rule action to obtain a second modified copied packet; and

forwarding the second modified copied packet to the egress pipeline.

15 . The method of claim 14 , wherein the method further comprises:

wherein modifying the copied packet comprises:

changing a source IP address of the packet to a modified source IP address, and

wherein modifying the second copied packet comprises:

changing a second source IP address of the second packet to the modified source IP address,

wherein the source IP address and the second source IP address are different.

16 . A network device, comprising:

an ingress pipeline;

an egress pipeline;

a packet translation module, comprising:

a packet translation diverter;

a packet translation agent;

a packet translation queue;

a packet translation ruleset;

a processor, executing the packet translation diverter, performs a method for modifying packet data of a packet, wherein the method comprises:

receiving, at the ingress pipeline, the packet;

performing a lookup, in the packet translation ruleset, to compare the packet data to rule criteria of a rule in the packet translation ruleset, the rule associated with a rule action;

making a first determination that at least a portion of the packet data matches the rule criteria; and

based on the first determination:

adding a packet translation tag to the packet, wherein the packet translation tag added to the packet comprises the rule action associated with the matching rule associated with the matching rule criteria, wherein the rule action describes a modification to perform on the packet;

wherein the processor, executing the packet translation agent, performs the method for modifying the packet data of the packet, wherein the method further comprises:

creating a copy of the packet by copying the packet translation tag comprising the rule action and at least a second portion of the packet data to obtain the copied packet;

modifying the copied packet according to the modification as described in the rule action included in the packet translation tag of the copied packet to obtain a modified copied packet; and

forwarding the modified copied packet to the egress pipeline.

17 . The network device of claim 16 , wherein modifying the copied packet comprises:

changing a destination IP address of the packet to a modified destination IP address.

18 . The network device of claim 17 , wherein modifying the copied packet further comprises:

changing a source IP address of the packet to a modified source IP address.

19 . The network device of claim 18 , wherein the source IP address and the destination IP address belong to a same first subnet.

20 . The network device of claim 19 , wherein the modified source IP address and the modified destination IP address do not belong to a same second subnet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2022
From: BORGIONE, SEBASTIANO; PEACH, JOHN S G
To: ARISTA NETWORKS, INC.
Reel/Frame 060338/0520 →
Continuity (2)
Provisional Application 63217880 · Jul 2, 2021
Related Publication 20230006928A1 · Jan 5, 2023
References Cited (8)
US 7689716B2 · Short et al. · 2010 [cited by examiner]
US 9210103B1 · Safrai · 2015 [cited by examiner]
US 9319351B1 · Orr et al. · 2016 [cited by examiner]
US 10374972B2 · Tremblay · 2019 [cited by examiner]
US 10652281B1 · Moolenaar · 2020 [cited by examiner]
US 20110134925A1 · Safrai et al. · 2011 [cited by examiner]
US 20150334045A1 · Tremblay · 2015 [cited by examiner]
US 20210044528A1 · Paduvalli · 2021 [cited by examiner]