IP Library Granted Patent US 12,549,507
Granted Patent B2
US 12,549,507 · App. 18/415,373 · Granted Feb 10, 2026

Method and system for efficient layer-2 forwarding between virtual machines

Inventors: Kedar Shrikrishna Patwardhan (Urbana, IL); Pratik Vijay Panjwani (San Jose, CA); Rutuja Umesh Madhure (Pune, IN); Sunil Khushal Patil (Pune, IN)
Assignee: Nutanix, Inc.
H04L61/103H04L61/5007H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,507
App. No.
18/415,373
Filed
Jan 17, 2024
Granted
Feb 10, 2026
Kind
B2
Examiner
ZONG, RUOLEI
Art Unit
2441
USPC
709/245
Abstract

A computing system is provided that enables efficient layer-2 traffic forwarding. During operation, the computing system can determine that a packet is from a first virtual machine (VM) running on the computing system and destined to a second VM running on a second computing system. The computing system can determine a first transit Internet Protocol (IP) address of a first VM and a second transit IP address of the second VM. The computing system can then modify the packet to replace existing media access control (MAC) addresses in the layer-2 header with MAC addresses of the computing system and the second computing system. The computing system can also modify the packet to replace the source and destination IP addresses in the layer-3 header with the first and second transit IP addresses, respectively. Subsequently, the computing system can determine an egress port based on the modified layer-2 header.

Claims (53)

1 . A method, comprising:

determining, by a computing system in a distributed system, that a packet is from a first virtual machine (VM) running on the computing system and destined to a second VM running on a second computing system;

determining a first transit Internet Protocol (IP) address of a first VM and a second transit IP address of the second VM, wherein a transit IP address of a respective VM is distinct from a primary IP address using which the VM participates in routing;

modifying a layer-2 header of the packet to replace source and destination media access control (MAC) addresses in the layer-2 header with a first MAC address of the computing system and a second MAC address of the second computing system, respectively;

modifying a layer-3 header of the packet to replace source and destination IP addresses in the layer-3 header of the packet with the first and second transit IP addresses, respectively; and

determining, for the packet, an egress port corresponding to the second computing system based on the modified layer-2 header.

2 . The method of claim 1 , further comprising:

mapping, at the computing system, the first transit IP address to IP and MAC addresses of a first VM; and

mapping, at the computing system, the second transit IP address to IP and MAC addresses of a second VM.

3 . The method of claim 2 , wherein the first and second VMs belong to a virtual private cloud (VPC) in the distributed system, and wherein the IP addresses of the first and second VMs are allocated from a first IP address space associated with the VPC.

4 . The method of claim 3 , wherein the first and second transit IP addresses are allocated from a second IP address space spanning a respective VPC in the distributed system, and wherein the second IP address space is distinct from the first IP address space.

5 . The method of claim 1 , wherein the computing system and the second computing system are in a same layer-2 forwarding domain.

6 . The method of claim 1 , further comprising:

receiving, from a management device, one or more flow rules instructing the computing system to modify layer-2 and layer-3 headers of an inter-VM packet; and

programming the one or more flow rules at the computing system.

7 . The method of claim 6 , further comprising receiving, from the management device, information indicating allocation of the first and second transit IP addresses to the first and second VMs, respectively.

8 . The method of claim 1 , further comprising:

receiving, from the first VM, an address resolution protocol (ARP) request for an IP address of the second VM;

generating an ARP response comprising a MAC address of the second VM from within the computing system; and

providing the ARP response to the first VM.

9 . A method, comprising:

determining, by a computing system of a distributed system running a first virtual machine (VM), that a packet is received from a second VM running on a second computing system;

obtaining a first transit Internet Protocol (IP) address of the first VM and a second transit IP address of the second VM from a layer-3 header of the packet, wherein a transit IP address of a respective VM is distinct from a primary IP address using which the VM participates in routing;

obtaining a first primary IP address and a first media access control (MAC) address of the first VM based on the first transit IP address;

obtaining a second primary IP address and a second MAC address of the second VM based on the second transit IP address;

modifying the packet to replace destination and source MAC addresses in a layer-2 header with the first and second MAC addresses, respectively;

modifying the packet to replace destination and source IP addresses in the layer-3 header with the first and second primary IP addresses, respectively; and

providing the modified packet to the second VM.

10 . The method of claim 9 , further comprising:

mapping, at the computing system, the first transit IP address to the first primary IP address and the first MAC address; and

mapping, at the computing system, the second transit IP address to the second primary IP address and the second MAC address.

11 . The method of claim 10 , wherein the first and second VMs belong to a virtual private cloud (VPC) in the distributed system, and wherein the first and second primary IP addresses are allocated from a first IP address space associated with the VPC.

12 . The method of claim 11 , wherein the first and second transit IP addresses are allocated from a second IP address space spanning a respective VPC in the distributed system, and wherein the second IP address space is distinct from the first IP address space.

13 . The method of claim 9 , wherein the computing system and the second computing system are in a same layer-2 forwarding domain.

14 . The method of claim 9 , further comprising:

receiving, from a management device, one or more flow rules instructing the computing system to modify layer-2 and layer-3 headers of an ingress inter-VM packet; and

programming the one or more flow rules at the computing system.

15 . The method of claim 14 , further comprising receiving, from the management device, information indicating allocation of the first and second transit IP addresses to the first and second VMs, respectively.

16 . The method of claim 9 , further comprising:

receiving, from the first VM, an address resolution protocol (ARP) request for an IP address of the second VM;

generating an ARP response comprising a MAC address of the second VM from within the computing system; and

providing the ARP response to the first VM.

17 . A computing system, comprising:

a processor; and

a memory coupled to the processor and storing instructions, which when executed by the processor cause the processor to perform a method, the method comprising:

determining that a packet is from a first virtual machine (VM) running on the computing system and destined to a second VM running on a second computing system;

determining a first transit Internet Protocol (IP) address of a first VM and a second transit IP address of the second VM, wherein a transit IP address of a respective VM is distinct from a primary IP address using which the VM participates in routing;

modifying a layer-2 header of the packet to replace source and destination media access control (MAC) addresses in the layer-2 header with a first MAC address of the computing system and a second MAC address of the second computing system, respectively;

modifying a layer-3 header of the packet to replace source and destination IP addresses in the layer-3 header of the packet with the first and second transit IP addresses, respectively; and

determining, for the packet, an egress port corresponding to the second computing system based on the modified layer-2 header.

18 . The computing system of claim 17 , wherein the first and second VMs belong to a virtual private cloud (VPC) in the distributed system, and wherein the first and second primary IP addresses are allocated from a first IP address space associated with the VPC.

19 . The computing system of claim 18 , wherein the first and second transit IP addresses are allocated from a second IP address space spanning a respective VPC, and wherein the second IP address space is distinct from the first IP address space.

20 . The computing system of claim 17 , wherein the computing system resides in a same layer-2 forwarding domain as the second computing system.

Assignments (2)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: PATWARDHAN, KEDAR SHRIKRISHNA; PANJWANI, PRATIK VIJAY; MADHURE, RUTUJA UMESH; PATIL, SUNIL KHUSHAL
To: NUTANIX, INC.
Reel/Frame 066181/0255 →
Continuity (1)
Related Publication 20250141831A1 · May 1, 2025
References Cited (32)
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8850130B1 · Aron et al. · 2014 [cited by applicant]
US 9772866B1 · Aron et al. · 2017 [cited by applicant]
US 20120177039A1 · Berman · 2012 [cited by examiner]
US 20210036889A1 · Jain · 2021 [cited by examiner]
US 20210360401A1 · Marinho · 2021 [cited by examiner]
US 20230179563A1 · Goodwin · 2023 [cited by examiner]
CN 112953884A · 2021 [cited by examiner]
WO WO2024140711A1 · 2024 [cited by examiner]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 4, 2015), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 12, 2016), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2016), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2017), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 8, 2017), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2018), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 25, 2018), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 8, 2019), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jul. 25, 2019), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 17, 2019), from https://nutanixbible.com/ pp. all. [cited by applicant]
Cano, Ignacio et al. “Curator: Self-Managing Storage for Enterprise Clusters”; University of Washington; published Mar. 2017; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 21, 2020), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 14, 2020), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Dec. 31, 2020), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jul. 27, 2022), from https://nutanixbible.com/ pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 16, 2024), from https://nutanixbible.com/ pp. all. [cited by applicant]
Citrix XenDesktop 7.1 on Microsoft Hyper-V Server 2012 R2 on Nutanix Virtual Computing Platform, Solution Design, Jun. 25, 2014. [cited by applicant]