IP Library Granted Patent US 12,255,811
Granted Patent B2
US 12,255,811 · App. 18/228,535 · Granted Mar 18, 2025

Fallback-aware policy-based routing

Inventors: Mary Preeti Manohar (Los Gatos, CA); Sragdhara Datta Chaudhuri (Cupertino, CA)
Assignee: Nutanix, Inc.
H04L45/42H04L45/22H04L45/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,811
App. No.
18/228,535
Filed
Jul 31, 2023
Granted
Mar 18, 2025
Kind
B2
Art Unit
2454
USPC
709/238
Abstract

Methods, systems, and computer program products for computer networking. Legacy policy-based routing is advanced by adding fallback-aware policy actions that are enabled within a policy-based routing regime. Upon determining that a destination specified in a subject policy is compromised, or down, or unreachable then, a fallback-aware policy action is invoked. Destinations specified in policies may refer to inserted services, wherein an inserted service can be any one of, a service process, a service virtual machine, a hardware network component, or a virtual network interface. Such inserted services might implement a logging service, or a firewall service, or other services that can process a network packet. Fallback-aware policy actions include, a PASSTHROUGH fallback action, an ALLOW fallback action, a FORWARD fallback action, and a DROP fallback action. Various techniques serve to determine whether or not a particular destination of a subject policy is deemed to be compromised, or down or unreachable.

Claims (35)

1. A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by a processor cause the processor to perform acts comprising:

adding respective fallback-aware policy actions to policies defined in a policy-based routing regime; and

observing fallback-aware policy action in a first policy matching a first packet when a first destination specified in the first policy is deemed to be compromised, down, or unreachable, wherein the fallback-aware policy action comprising temporarily disabling the first policy; and

observing, after temporarily disabling the first policy, an action in a second policy matching the first packet when a second destination specified in the second policy is not deemed to be compromised, down, or unreachable, wherein the action comprise routing to a destination identified in the action of the second policy and the first policy is observed before the second policy is observed based on at least the first policy having a higher priority than the second policy.

2. The non-transitory computer readable medium of claim 1 , wherein the destination specified in the second policy is an inserted service, and wherein the inserted service is at least one of, a service process, a service virtual machine, a hardware network component, or a virtual network interface.

3. The non-transitory computer readable medium of claim 2 , wherein the inserted service implements at least one of, a logging service, a telemetry service, or a firewall service.

4. The non-transitory computer readable medium of claim 1 , the policy specifies a policy-based reroute destination and wherein the fallback-aware policy action is one of, a PASSTHROUGH fallback action, an ALLOW fallback action, a FORWARD fallback action, or a DROP fallback action.

5. The non-transitory computer readable medium of claim 4 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the PASSTHROUGH fallback action routes a packet to the destination specified in the packet rather than to the policy-based reroute destination.

6. The non-transitory computer readable medium of claim 4 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the ALLOW fallback action routes a packet to the policy-based reroute destination rather than to the destination specified in the packet.

7. The non-transitory computer readable medium of claim 4 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the DROP fallback action drops a packet rather than routing the packet to the policy-based reroute destination.

8. The non-transitory computer readable medium of claim 4 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the FORWARD fallback action routes a packet to a destination address in the packet, rather than routing the packet to the policy-based reroute destination.

9. A method comprising:

adding respective fallback-aware policy actions to policies defined in a policy-based routing regime; and

observing fallback-aware policy action in a first policy matching a first packet when a first destination specified in the first policy is deemed to be compromised, down, or unreachable, wherein the fallback-aware policy action comprising temporarily disabling the first policy; and

observing, after temporarily disabling the first policy, an action in a second policy matching the first packet when a second destination specified in the second policy is not deemed to be compromised, down, or unreachable, wherein the action comprise routing to a destination identified in the action of the second policy and the first policy is observed before the second policy is observed based on at least the first policy having a higher priority than the second policy.

10. The method of claim 9 , wherein the destination specified in the second policy is an inserted service, and wherein the inserted service is at least one of, a service process, a service virtual machine, a hardware network component, or a virtual network interface.

11. The method of claim 10 , wherein the inserted service implements at least one of, a logging service, a telemetry service, or a firewall service.

12. The method of claim 9 , the policy specifies a policy-based reroute destination and wherein the fallback-aware policy action is one of, a PASSTHROUGH fallback action, an ALLOW fallback action, a FORWARD fallback action, or a DROP fallback action.

13. The method of claim 12 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the PASSTHROUGH fallback action routes a packet to the destination specified in the packet rather than to the policy-based reroute destination.

14. The method of claim 12 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the ALLOW fallback action routes a packet to the policy-based reroute destination rather than to the destination specified in the packet.

15. The method of claim 12 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the DROP fallback action drops a packet rather than routing the packet to the policy-based reroute destination.

16. The method of claim 12 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the FORWARD fallback action routes a packet to a destination address in the packet, rather than routing the packet to the policy-based reroute destination.

17. A system comprising:

a storage medium having stored thereon a sequence of instructions; and

a processor that executes the sequence of instructions to cause the processor to perform acts comprising,

adding respective fallback-aware policy actions to policies defined in a policy-based routing regime; and

observing fallback-aware policy action in a first policy matching a first packet when a first destination specified in the first policy is deemed to be compromised, down, or unreachable, wherein the fallback-aware policy action comprising temporarily disabling the first policy; and

observing, after temporarily disabling the first policy, an action in a second policy matching the first packet when a second destination specified in the second policy is not deemed to be compromised, down, or unreachable, wherein the action comprise routing to a destination identified in the action of the second policy and the first policy is observed before the second policy is observed based on at least the first policy having a higher priority than the second policy.

18. The system of claim 17 , wherein the destination specified in the second policy is an inserted service, and wherein the inserted service is at least one of, a service process, a service virtual machine, a hardware network component, or a virtual network interface.

19. The system of claim 18 , wherein the inserted service implements at least one of, a logging service, a telemetry service, or a firewall service.

20. The system of claim 17 , the policy specifies a policy-based reroute destination and wherein the fallback-aware policy action is one of, a PASSTHROUGH fallback action, an ALLOW fallback action, a FORWARD fallback action, or a DROP fallback action.

21. The system of claim 20 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the PASSTHROUGH fallback action routes a packet to the destination specified in the packet rather than to the policy-based reroute destination.

22. The system of claim 20 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the ALLOW fallback action routes a packet to the policy-based reroute destination rather than to the destination specified in the packet.

23. The system of claim 20 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the DROP fallback action drops a packet rather than routing the packet to the policy-based reroute destination.

24. The system of claim 20 , wherein, when the policy-based reroute destination is deemed to be down or unreachable, the FORWARD fallback action routes a packet to a destination address in the packet, rather than routing the packet to the policy-based reroute destination.

Assignments (2)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2023
From: MANOHAR, MARY PREETI; CHAUDHURI, SRAGDHARA DATTA
To: NUTANIX, INC.
Reel/Frame 064441/0001 →
Continuity (1)
Related Publication 20250047594A1 · Feb 6, 2025
References Cited (28)
US 7877505B1 · Oz · 2011 [cited by examiner]
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8850130B1 · Aron et al. · 2014 [cited by applicant]
US 9264400B1 · Lin · 2016 [cited by examiner]
US 9772866B1 · Aron et al. · 2017 [cited by applicant]
US 20030097557A1 · Tarquini · 2003 [cited by examiner]
US 20160294677A1 · Kazerani · 2016 [cited by examiner]
US 20180262454A1 · Zandi · 2018 [cited by examiner]
US 20200076734A1 · Naveen · 2020 [cited by examiner]
US 20230269128A1 · Mullis · 2023 [cited by examiner]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jul. 9, 2019), from htis xbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Feb. 3, 2020), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Aug. 1, 2020), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 30, 2021), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 9, 2022), from https://nutanixbible.com/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Cano, I. et al., “Curator: Self-Managing Storage for Enterprise Clusters”, [cited by applicant]
“Citrix XenDesktop 7.1 on Microsoft Hyper-V Server 2012 R2 on Nutanix Virtual Computing Platform—Solution Design,” Citrix Validated Solutions, Prepared by: Citrix APAC Solutions, dated Jun. 25, 2014. [cited by applicant]
Joseph, D., et al., “A Policy-aware Switching Layer for Data Centers,” University of California at Berkeley, SIGCOMM'08, Aug. 17-22, 2008. [cited by applicant]
“Chapter 26: Configuring Policy-Based Routing,” Cisco Software Configuration Guide—Release 12.2(25)EW, date found via Google as Mar. 21, 2015. [cited by applicant]
Katsikogiannis, G., et al., “Policy-Based QoS Management for SLA-Driven Adaptive Routing,” Department of Informatics, University of Piraeus, Journal of Communications and Networks, Jun. 2013. [cited by applicant]
Katsikogiannis, G., et al., “A PBNM System for adaptive routing,” Department of Informatics, University of Piraeus, dated Sep. 2011. [cited by applicant]
Al-Madi, M., et al., “A Proposed Model for Policy-Based Routing Rules in the IPV6 Offering QoS for IPTV Broadcasting,” IJCSNS International Journal of Computer Science and Network Security, vol. 8 No. 3, Mar. 2008. [cited by applicant]