IP Library Granted Patent US 9,389,961
Granted Patent B1
US 9,389,961 · App. 14/503,392 · Granted Jul 12, 2016

Automated network isolation for providing non-disruptive disaster recovery testing of multi-tier applications spanning physical and virtual hosts

Inventors: Swapnil Patankar (Thane, IN); Shrikant Ghare (Pune, IN)
Assignee: Veritas Technologies LLC
G06F11/1448G06F11/2028G06F11/2097G06F17/30575H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,389,961
App. No.
14/503,392
Granted
Jul 12, 2016
Kind
B1
Abstract

Various systems, methods and apparatuses for creating network isolation spanning physical and virtual hosts are presented. In one embodiment, network isolation may be created between a primary (e.g., production) site and a secondary (e.g., a disaster recovery or sandbox) site. The network isolation allows testing (or other uses) on the secondary site to be non-disruptive to the normal operations of the sites, including the ability to failover during testing. Such non-disruptive network isolation allows certain communications to continue, especially communications between ports having replicated data. The network isolation may be customized in various other ways to allow certain communications to continue while preventing other communications. This invention can be used to validate application readiness, as well as to validate data correctness of individual tiers, and may be used with systems that contain multiple tiers, and include physical hosts, virtual hosts, and/or combinations of both.

Claims (87)

1. A method comprising:

replicating data from a production site to a secondary site, wherein

the secondary site is configured with a secondary multi-tier application, and

the secondary multi-tier application is a copy of a primary multi-tier application executing on the production site;

configuring a firewall to provide network isolation between the primary multi-tier application and the secondary multi-tier application, wherein

the configuring the firewall allows the replicating to occur between the production site and the secondary site while the network isolation is ongoing; and

testing the secondary multi-tier application, wherein the testing comprises

testing the secondary multi-tier application while the replicating is ongoing.

2. The method of claim 1 , wherein the configuring the firewall further comprises

configuring the firewall to allow the secondary site to perform one or more operations that are not part of the testing, wherein

the one or more operations are performed during the testing.

3. The method of claim 1 , further comprising

using one or more daemons on the production site to collect one or more parameters from the production site, wherein

the one or more daemons collect the one or more parameters prior to the configuring the firewall.

4. The method of claim 3 , further comprising

providing the one or more parameters to one or more daemons on the secondary site, wherein

the providing occurs prior to the configuring the firewall.

5. The method of claim 1 , further comprising

updating a hostname mapping table, wherein

the hostname mapping table is stored on the secondary site prior to the testing, and

the hostname mapping table is used during the testing.

6. The method of claim 1 , further comprising

creating a clone of one or more service groups, wherein

each clone corresponds to a service group on the secondary site,

each clone corresponds to a service group on the production site, and

the creating the clone of each of the one or more service groups is performed prior to the testing.

7. The method of claim 1 , further comprising

stopping the testing prior completion of the testing, wherein

the stopping is performed in response to detecting a failure related to the production site; and

bringing the secondary site online in response to the detecting the failure.

8. A non-transitory computer-readable storage medium configured to store program instructions that, when executed on a processor, are configured to cause the processor to perform a method comprising:

replicating data from a production site to a secondary site, wherein

the secondary site is configured with a secondary multi-tier application, and

the secondary multi-tier application is a copy of a primary multi-tier application executing on the production site;

configuring a firewall to provide network isolation between the primary multi-tier application and the secondary multi-tier application, wherein

the configuring the firewall allows the replicating to occur between the production site and the secondary site while the network isolation is ongoing; and

testing the secondary multi-tier application, wherein the testing comprises

testing the secondary multi-tier application while the replicating is ongoing.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the configuring the firewall further comprises:

configuring the firewall to allow the secondary site to perform one or more operations that are not part of the testing, wherein

the one or more operations are performed during the testing.

10. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises:

using one or more daemons on the production site to collect one or more parameters from the production site, wherein

the one or more daemons collect the one or more parameters prior to the configuring the firewall.

11. The non-transitory computer-readable storage medium of claim 10 , wherein the method further comprises:

providing the one or more parameters to one or more daemons on the secondary site, wherein

the providing occurs prior to the configuring the firewall.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises:

updating a hostname mapping table, wherein

the hostname mapping table is stored on the secondary site prior to the testing, and

the hostname mapping table is used during the testing.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises:

creating a clone of one or more service groups, wherein

each clone corresponds to a service group on the secondary site,

each clone corresponds to a service group on the production site, and

the creating the clone of each of the one or more service groups is performed prior to the testing.

14. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises:

creating a clone of one or more service groups, wherein

each clone corresponds to a service group on the secondary site,

each clone corresponds to a service group on the production site, and

the creating the clone of each of the one or more service groups is performed prior to the performing the test.

15. The non-transitory computer-readable storage medium of claim 8 , wherein the method further comprises:

stopping the testing prior completion of the testing, wherein

the stopping is performed in response to detecting a failure related to the production site; and

bringing the secondary site online in response to the detecting the failure.

16. A computer system comprising:

a processor; and

a memory coupled to the processor and configured to store instructions executable by the processor, the instructions configured to

replicate data from a production site to a secondary site, wherein

the secondary site is configured with a secondary multi-tier application, and

the secondary multi-tier application is a copy of a primary multi-tier application executing on the production site;

configure a firewall to provide network isolation between the primary multi-tier application and the secondary multi-tier application, wherein

the firewall is configured to allow the data to be replicated between the production site and the secondary site while the network isolation is ongoing; and

test the secondary multi-tier application, wherein the test comprises

testing the secondary multi-tier application while the data is being replicated.

17. The computer system of claim 16 , wherein

the firewall is further configured to allow the secondary site to perform one or more operations that are not part of the test, and

the one or more operations are performed during the test.

18. The computer system of claim 16 , wherein the instructions are further configured to use one or more daemons on the production site to collect one or more parameters from the production site, wherein

the one or more daemons collect the one or more parameters prior to the firewall being configured.

19. The computer system of claim 16 , wherein the instructions are further configured to update a hostname mapping table, wherein

the hostname mapping table is stored on the secondary site prior to the test, and

the hostname mapping table is used during the test.

20. The computer system of claim 16 , wherein the instructions are further configured to create a clone of one or more service groups, wherein

each clone corresponds to a service group on the secondary site,

each clone corresponds to a service group on the production site, and

the clone of each of the one or more service groups is created prior to the test.

Assignments (14)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038483/0203 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037693/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2014
From: GHARE, SHRIKANT
To: SYMANTEC CORPORATION
Reel/Frame 034264/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2014
From: PATANKAR, SWAPNIL
To: SYMANTEC CORPORATION
Reel/Frame 034246/0458 →