Allocating additional bandwidth for resources in a data center through the deployment of a dedicated gateway
By deploying edge forwarding components in SDDC and creating traffic groups, the resource allocation problem of large bandwidth flows in SDDC is solved, and more efficient network resource utilization and management is achieved.
Patent Information
- Application Number
- CN202180064148.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-06
- Filing Date
- 2021-07-17
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-07-17
AI Technical Summary
In the prior art, software-defined data centers (SDDCs) cannot effectively utilize edge network resources when processing flows with large bandwidth requirements, resulting in increased management overhead and no effective solution to allocate dedicated bandwidth resources for large streams.
Deploy the default first edge forwarding element in the SDDC to process the data message flow, and upon receiving the bandwidth request, the deploy the second edge forwarding element allocates more bandwidth to a specific set of data message flows, while processing other streams through the default edge nodes, optimizing bandwidth allocation by identifying network addresses and creating traffic groups.
It realizes that more bandwidth is allocated to a specific data message stream set in SDDC, reduces management overhead, improves network resource utilization efficiency, and meets the bandwidth requirements of large streams.
Smart Images

Figure CN116210209B_ABST
Abstract
Description
[0001] Dileep Devireddy,Ganesh Sadasivan,Chidambareswaran Raman,Hongwei Zhu,Sreenivas Duvvuri BACKGROUND OF THE INVENTION
[0002] Software-defined data centers (SDDCs) are typically protected from external networks by edge routers that perform middlebox service operations such as firewalls, network address translation (NAT), etc. All external traffic is directed through the edge gateway. The external network bandwidth in an SDDC is determined by the minimum of the edge gateway uplink bandwidth and the host adapter network bandwidth. There are applications with flows that require large bandwidths, and these flows consume a large amount of edge network capacity. These flows are often stateful, which requires traffic to be symmetrically processed on the same edge router. There is currently no solution to address these requirements. Because of this, customers are often required to split their applications across multiple SDDCs so that they can obtain additional external network bandwidth. Each SDDC has its own management plane and this results in management overhead. There is a need to be able to allocate dedicated bandwidth resources for large flows within the same SDDC. SUMMARY OF THE INVENTION
[0003] Some embodiments of the present invention provide a method for deploying edge forwarding elements in a public or private software-defined data center (SDDC). For an entity (e.g., tenant, enterprise, department, etc.), the method deploys a default first edge forwarding element to handle data message flows between machines of the entity in a first network of the SDDC and machines external to the first network of the SDDC (e.g., machines outside the SDDC). The method then receives a request to allocate more bandwidth to a first set of data message flows entering or leaving the first network of the SDDC.
[0004] In response, the method deploys a second edge forwarding element to handle the first set of data message flows of the entity so as to allocate more bandwidth to the first set of data message flows while continuing to handle a second set of data message flows of the entity through the default first edge section. The method of some embodiments provides a novel way of making bandwidth available as any other user-selectable resource in an SDDC, such as a computer, service machine, network element, etc.
[0005] In some embodiments, the method receives a request for more bandwidth by first receiving a request to create a traffic group and then receiving a list of network addresses associated with the traffic group. The list of network addresses identifies a subset of data message flows to be processed by a second edge node. In some embodiments, the network addresses are network addresses associated with interfaces of forwarding elements used to connect machines in a first network to the first network. In some embodiments, the method receives the list of network addresses associated with the traffic group by receiving a prefix of the network addresses and then receiving a request to associate the prefix of the network addresses with the traffic group. Based on this request, the method then creates an association between the traffic group and the received prefix of the network addresses.
[0006] In some embodiments, the method deploys a second edge forwarding element by configuring a second edge forwarding element to forward a first set of data messages to a forwarding element in an external network and configuring a set of forwarding elements in the first network to forward a first set of data message flows from a set of machines in the first network to the second edge forwarding element. In some embodiments, the edge forwarding element is an edge router. In some of these embodiments, the method configures the second edge forwarding element by configuring the second edge forwarding element to advertise routes to the set of machines to a forwarding element in the external network.
[0007] In some embodiments, the set of configured forwarding elements in the first network includes intermediate routers. In some of these embodiments, the method configures the set of intermediate routers by providing next-hop forwarding rules to the set of intermediate routers. Alternatively or in combination, in some embodiments, the set of configured forwarding elements includes a set of intermediate switches implementing a logical switch. In these embodiments, the method configures the set of intermediate switches by providing forwarding rules to the set of intermediate switches to direct the switches to forward a first set of data message flows to the second edge forwarding element through a set of tunnels that connect the set of intermediate routers to the second edge forwarding element.
[0008] In some embodiments, the SDDC is a public cloud data center having a second network. In these embodiments, the first network is a private network defined within the second network to implement a virtual private cloud (VPC) for entities in the public cloud data center. The first network is in some embodiments an isolated private physical network, while in other embodiments it is a logical overlay network.
[0009] In some embodiments, the second edge forwarding element is a gateway in a public cloud data center. In some embodiments, the method deploys the second edge forwarding element by deploying a gateway and then configuring a set of forwarding elements in a second network of the public cloud data center to forward a first set of data message flows to the deployed gateway.
[0010] In some embodiments, the method deploys the first and second edge forwarding elements by deploying the first and second edge forwarding elements as separate first and second devices in an SDDC. In some embodiments, the first and second devices are different edge forwarding apparatuses. In other embodiments, the first and second edge forwarding devices are two different machines executing on two different host computers.
[0011] After receiving a request to allocate more bandwidth to a first set of data message flows, the method of some embodiments receives a request to allocate more bandwidth to a third set of data message flows to an entity entering or leaving a first network of the SDDC. The method deploys a third edge forwarding element for the entity to handle the third set of data message flows in order to allocate more bandwidth to the third set of data message flows while continuing to process a second set of data message flows through a default first edge node and a first set of data message flows through a second edge node.
[0012] Similar to a request to allocate more bandwidth to a first set of data message flows, in some embodiments, the method receives a request for more bandwidth for a third set of data message flows by first receiving a request to create another traffic group, receiving another prefix identifying a network address of the third set of data message flows, and then receiving a request to associate the newly received traffic group with the newly received address prefix. In some embodiments, the address prefixes for the first and third data message flows may overlap. In such cases, the method resolves the overlap by assigning the overlapping addresses to the traffic group that more specifically identifies the address. For example, if a first list of addresses for the first set of data message flows is specified according to a range of IP addresses (192.168.200.0 / 24), and a second list of addresses for the third set of data message flows specifies a specific address (192.168.200.10) within this range, then the method assigns the more specific address to a second traffic group identifying the third set of data message flows.
[0013] In some embodiments, the method deploys the second and third edge forwarding elements by deploying them as different forwarding devices, while in other embodiments, the method deploys these forwarding elements by different machines executing on different host computers in the SDDC. Using different host computers for different sets of data message flows allows dedicated resources (e.g., physical network interface cards (PNICs)) of different host computers to be used for different sets of data message flows.
[0014] The foregoing Summary is intended to serve as a brief introduction to some embodiments of the present invention. It is not meant to be an introduction or overview of all inventive subject matter disclosed in this document. The following Detailed Description and the accompanying drawings referred to in the Detailed Description will further describe the embodiments described in the Summary as well as other embodiments. Accordingly, a thorough review of the Summary, Detailed Description, drawings, and claims is needed to understand all of the embodiments described in this document. Moreover, the claimed subject matter is not limited by the illustrative details set forth in the Summary, Detailed Description, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The novel features of the invention are set forth in the appended claims. However, for explanatory purposes, several embodiments of the invention are set forth in the following drawings.
[0016] Figures 1-3 An example is illustrated of deploying multiple edge gateways in an SDDC to allocate additional bandwidth to multiple different sets of ingress and egress flows to and from machines deployed for entities in the SDDC.
[0017] Figure 4 A conceptual diagram illustrates the process performed by a manager and a controller server in some embodiments to define and deploy traffic groups to allocate additional bandwidth to a set of machines.
[0018] Figure 5 An example of a management user interface for some embodiments for defining and creating traffic groups is illustrated.
[0019] Figure 6 A display window is illustrated that is displayed after selecting a traffic group control.
[0020] Figure 7 An illustration shows adding a newly created traffic group to the traffic groups listed in a traffic group pane.
[0021] Figure 8 An IP prefix list pane including an add IP prefix list control is shown.
[0022] Figure 9 A selection of a prefix list control is shown.
[0023] Figure 10 Illustrates the display window presented after selecting the prefix list control.
[0024] Figure 11 Illustrates the prefix setting window, while Figure 12 Illustrates the prefix pane.
[0025] Figure 13 Illustrates the prefix setting window that displays the specified prefix along with the user's selection of application controls to direct the management server to associate the specified prefix list with the prefix name.
[0026] Figure 14 Illustrates the prefix pane after selecting the application control.
[0027] Figures 15-18 Illustrates the association of the received list of network addresses with the traffic group.
[0028] Figure 19 Illustrates the computer system by which each embodiment of the present invention can be implemented. Detailed Description
[0029] In the following detailed description of the present invention, many details, examples, and embodiments of the present invention are set forth and described. However, it will be apparent to those skilled in the art that the present invention is not limited to the described embodiments, and the present invention can be practiced without discussing some of the specific details and examples.
[0030] Some embodiments of the present invention provide a method for deploying edge forwarding elements in a public or private software-defined data center (SDDC). For an entity (e.g., a tenant, enterprise, department, etc.), the method deploys a default first edge forwarding element to handle data message flows between machines of the entity in the first network of the SDDC and machines outside the first network of the SDDC (e.g., machines outside the SDDC). The method then receives a request to allocate more bandwidth to a first set of data message flows entering or leaving the first network of the SDDC.
[0031] In response, the method deploys a second edge forwarding element to handle the first set of data message flows of the entity in order to allocate more bandwidth to the first set of data message flows, while continuing to process a second set of data message flows of the entity through the default first edge section. The method of some embodiments provides a novel way of making bandwidth available as any other user-selectable resource in the SDDC, such as computer machines, service machines, network elements, etc.
[0032] In some embodiments, the method receives a request for more bandwidth by first receiving a request to create a traffic group and then receiving a list of network addresses associated with the traffic group. The list of network addresses identifies a subset of data message flows to be processed by a second edge node. In some embodiments, the network addresses are network addresses associated with interfaces of forwarding elements used to connect machines in a first network to the first network. In some embodiments, the method receives the list of network addresses associated with the traffic group by receiving a prefix of the network addresses and then receiving a request to associate the prefix of the network addresses with the traffic group. Based on this request, the method then creates an association between the traffic group and the received prefix of the network addresses.
[0033] In some embodiments, the method deploys a second edge forwarding element by configuring the second edge forwarding element to forward a first set of data messages to a forwarding element in an external network and configuring a set of forwarding elements in the first network to forward a first set of data message flows from a set of machines in the first network to the second edge forwarding element. In some embodiments, the edge forwarding element is an edge router. In some of these embodiments, the method configures the second edge forwarding element by configuring the second edge forwarding element to advertise routes to the set of machines to a forwarding element in the external network.
[0034] After receiving a request to allocate more bandwidth to a first set of data message flows, the method of some embodiments receives a request to allocate more bandwidth to a third set of data message flows to an entity in the first network entering or leaving the SDDC. The method deploys a third edge forwarding element for the entity to process the third set of data message flows in order to allocate more bandwidth to the third set of data message flows while continuing to process a second set of data message flows passing through a default first edge node and a first set of data message flows passing through a second edge node.
[0035] Similar to the request to allocate more bandwidth to a first set of data message flows, in some embodiments, the method receives a request for more bandwidth for a third set of data message flows by first receiving a request to create another traffic group, receiving another prefix of network addresses identifying the third set of data message flows, and then receiving a request to associate the newly received traffic group with the newly received address prefix. In some embodiments, the address prefixes for the first and third data message flows may overlap. In such cases, the method resolves the overlap by assigning the overlapping addresses to the traffic group that more specifically identifies the addresses.
[0036] For example, if a first list of addresses for a first set of data message flows is specified according to a range of IP addresses (192.168.200.0 / 24), and a second list of addresses for a third set of data message flows specifies a specific address (192.168.200.10) within this range, then the method assigns the more specific address to a second traffic group that identifies the third set of data message flows. Alternatively, a first list of addresses can be specified according to a first range of IP addresses (192.168.200.0 / 24), and a second list of addresses can be specified as a smaller second range (192.168.200.0 / 32) of IP addresses within the first range. In this case, the method assigns the more specific address (i.e., the smaller range 192.168.200.0 / 32) to a second traffic group that identifies the third set of data message flows and assigns the remaining IP addresses within the larger range (the remaining addresses in 192.168.200.0 / 24) to a first traffic group.
[0037] In some embodiments, the method deploys second and third edge forwarding elements by deploying them as different forwarding devices, while in other embodiments, the method deploys these forwarding elements by different machines executing on different host computers in the SDDC. Using different host computers for different sets of data message flows allows different resources of the different host computers (e.g., physical network interface cards (PNICs)) to be used for different sets of data message flows.
[0038] As used in this document, a data message refers to a collection of bits in a specific format sent across a network. One of ordinary skill in the art will recognize that the term data message is used in this document to refer to various formatted collections of bits sent across a network. The formatting of these bits can be specified by a standardized protocol or a non-standardized protocol. Examples of data messages that follow a standardized protocol include Ethernet frames, IP packets, TCP segments, UDP datagrams, etc. Also, as used in this document, references to the L2, L3, L4, and L7 layers (or the second, third, fourth, and seventh layers) respectively refer to the second data link layer, third network layer, fourth transport layer, and seventh application layer of the OSI (Open System Interconnection) layer model.
[0039] In some embodiments, the edge forwarding element is an edge gateway that connects a private first network of an entity to an external network (e.g., a network connected to the SDDC or an external network outside the SDDC). Figures 1-3Illustrated is an example of deploying multiple edge gateways in an SDDC to allocate additional bandwidth to multiple different sets of ingress and egress traffic to and from machines deployed in the SDDC for an entity. In this example, the SDDC is public cloud availability zone 102, in which a virtual private cloud (VPC) 100 has been defined for the entity, which in this example is a tenant of a private cloud. In some embodiments, an availability zone includes one data center or more than one data center in close proximity to each other. Although Figures 1-3 illustrated are uses of some embodiments in a public cloud context, those of ordinary skill in the art will recognize that some embodiments of the present invention can be implemented similarly in a private data center.
[0040] For the entity, VPC 100 includes a private network 105 formed by a number of forwarding elements (e.g., switches and routers), which are not shown in these figures to avoid obscuring the figures with unnecessary details. The forwarding elements include software forwarding elements (e.g., software switches and routers) and middlebox elements (e.g., firewalls, load balancers, etc.) executed on multi-tenant host computers 115 and machines 110 deployed for the entity. In some embodiments, the forwarding elements also include hardware forwarding elements and / or middlebox elements (e.g., hardware switching and / or router devices, and / or middlebox devices).
[0041] In some embodiments, private network 105 is established by fragmenting the internal network address space of the private cloud and providing a set of internal network addresses to private network 105 that does not overlap with the internal network addresses provided to any other tenant of the VPC. In other embodiments, private network 105 is a logical overlay network formed by establishing tunnels between the forwarding elements of the private network and causing the forwarding elements to exchange data messages through these tunnels, e.g., by encapsulating the data messages with tunnel headers, which allows data messages to be exchanged between the forwarding elements while preserving the original data message headers containing the network addresses defined in the logical address space. In some embodiments, the logical address space of one tenant can overlap with the logical address space of another tenant, but this is not significant because the tunnel headers are encapsulated.
[0042] Figure 1Illustrated is a default gateway 120, which is initially deployed by a set of controllers 130 to connect a VPC network 105 to a first external network. The first external network in this example is a network inside a public cloud data center 102. In this example, any VPC gateway (including the default gateway 120) connects to (i.e., forwards packets to) one or more gateways 135 of the public cloud data center 102, which communicate with an external network 145 outside the public cloud data center 102. In other embodiments, the VPC gateway (including the default gateway 120) directly connects to the external network 145 without having to go through any gateway 135 of the public cloud data center 102.
[0043] In some embodiments, the set of controllers 130 configures the default gateway 120 to forward ingress data messages from the cloud gateway 135 to the VPC network and to forward egress data messages from the VPC network to the cloud gateway 135. In some embodiments, the set of controllers also configures forwarding elements in the VPC network 105 to forward egress data messages to the default gateway 120 and to forward ingress data messages to machines 110 of the VPC network.
[0044] Figure 2 Illustrated is the VPC 100 after a gateway 220 has been created for a first traffic group (TG). This traffic group includes a set of machines 200, including machines 110d and 110e. In some embodiments, the set of machines 200 includes a group of machines for which an administrator of an entity has requested more bandwidth. In some embodiments, the administrator requests this additional bandwidth by first creating a traffic group in an administrative portal provided by a set of manager servers 125 and then providing a list of network addresses associated with the traffic group.
[0045] In some embodiments, the list of network addresses is the network addresses associated with interfaces used to connect machines in the set of machines 200 to forwarding elements in the VPC network 105. In some embodiments, the administrator provides the list of network addresses associated with the traffic group by first providing a prefix of the network addresses and then requesting that this prefix of network addresses be associated with the traffic group. Based on this request, the manager server 125 directs the controller server 130 to create an association between the traffic group and the received prefix of network addresses.
[0046] The list of network addresses provided by the administrator for the first TG identifies a subset of data message flows to be processed by the gateway 220 of the first traffic group. Specifically, for the first traffic group, the controller set 130 deploys the first TG gateway 220. In some embodiments, it is important that the same TG gateway processes the ingress and egress data message flows for the traffic group machines because the gateway needs to maintain state and / or perform stateful middlebox services (such as firewalls, load balancing, etc.) for that traffic group. In some embodiments, each gateway (e.g., the default gateway and each TG gateway) maintains state and / or performs stateful middlebox services on the ingress and / or egress traffic entering and / or leaving the VPC network.
[0047] In some of these embodiments, the controller set employs destination-side routing to ensure that the cloud gateway 135 forwards all ingress data messages to the first traffic group (i.e., all data messages destined for the list of network addresses provided for the first traffic group) to the TG gateway 220, and employs source-side routing to ensure that the forwarding elements of the VPC network 105 forward all egress data messages from the first traffic group (i.e., all egress data messages originating from the list of network addresses provided for the first traffic group) to the TG gateway 220.
[0048] More specifically, the controller set 130 configures the cloud gateway 135 to forward ingress data messages destined for the network addresses provided for the first traffic group to the first TG gateway 220. The controller set 130 also configures the first TG gateway 220 to forward these ingress data messages from the cloud gateway 135 to the VPC network 105, and to forward egress data messages from the first TG machine 200 to the cloud gateway 135. In some embodiments, the controller server also configures the first TG gateway 220 to advertise routes to the list of network addresses associated with the TG to the cloud gateway 135. In some embodiments, the controller set 130 also configures the forwarding elements in the VPC network 105 to forward egress data messages having source addresses provided in the list of addresses of the first traffic group (i.e., all egress data messages from the set of machines 200 of the first traffic group) to the first TG gateway 220. It also configures these forwarding elements to forward ingress data messages destined for the network addresses associated with the TG to the set of machines 200.
[0049] In some embodiments, the forwarding elements in the VPC network 105 include intermediate routers. In some embodiments, the controller set 130 configures these intermediate routers in the VPC network 105 by providing next-hop forwarding rules to a set of intermediate routers. Alternatively or in combination, in some embodiments, the set of configured forwarding elements includes a set of intermediate switches that implement logical switches. In these embodiments, the method configures the set of intermediate switches by providing forwarding rules to the set of intermediate switches to direct the switches to forward a first set of data message flows to the first TG gateway 220 through a tunnel that connects the set of intermediate switches to the first TG gateway 220.
[0050] Figure 3 Illustrated is the VPC 100 after a gateway 320 has been created for a second traffic group (TG). This traffic group includes a set of machines 300, including machines 110b and 110c. In some embodiments, the set of machines 300 includes a group of machines for which an entity administrator has requested more bandwidth. In some embodiments, the administrator requests this additional bandwidth by first creating a second traffic group in the management portal and then providing a list of network addresses associated with the second traffic group. In some embodiments, the list of addresses provided is the network addresses associated with the interfaces used to connect the machines in the set of machines 300 to the forwarding elements in the VPC network 105. Similar to the addresses for the first traffic group, in some embodiments, the administrator provides network addresses for the second traffic group by first providing a prefix of the network addresses and then requesting that this prefix of network addresses be associated with the second traffic group. Based on this request, the manager set 125 directs the controller set 130 to create an association between the second traffic group and the prefix of the network addresses received for this group.
[0051] For the second traffic group, the controller set 130 deploys a second TG gateway 320. Just as it did for the first traffic group, the controller set employs destination-side routing to ensure that the cloud gateway 135 forwards all incoming data messages to the second traffic group (i.e., all data messages destined for the network addresses provided for the second traffic group) to the second TG gateway 320, and employs source-side routing to ensure that the forwarding elements in the VPC network 105 forward all outgoing data messages from the second traffic group (i.e., all outgoing data messages originating from the list of network addresses provided for the second traffic group) to the second TG gateway 320.
[0052] The controller set 130 also configures the second TG gateway 320 to forward the ingress data messages from the cloud gateway 135 to the VPC network 105 and forward the egress data messages from the second TG machine 300 to the cloud gateway 135. In some embodiments, the controller set also configures the second TG gateway 320 to announce the routes to the network addresses associated with the second traffic group to the cloud gateway 135. In some embodiments, the controller set 130 also configures the forwarding elements in the VPC network 105 to forward the ingress data messages destined for the network addresses associated with the second TG to the machine set 300.
[0053] After the controller set 130 configures the first TG and the second TG gateways 220 and 320, the first gateway 220 forwards all the ingress and egress traffic for the first traffic group machines, the second gateway 320 forwards all the ingress and egress traffic for the second traffic group machines, and the default gateway 120 forwards all the ingress and egress traffic for the entity machines not in the first and second traffic groups.
[0054] In some embodiments, each of the gateways 120, 220, or 320 is a logical gateway implemented by a high-availability (HA) pair of physical gateways, with the physical gateways in an HA active-standby configuration, as further described below. Moreover, in some embodiments, each gateway is deployed as a separate device. In other embodiments, each gateway is deployed as a machine executing on a host computer (e.g., a multi-tenant host computer or a stand-alone host computer). In some of these embodiments, different gateways are deployed on different host computers to maximize the throughput of each gateway. Using different host computers for different traffic groups to implement different gateways allows the dedicated resources (e.g., physical network interface cards (PNICs)) of different host computers to be used for the data message flows of different traffic groups.
[0055] Figure 4 The conceptual diagram illustrates a process 400 performed by the manager and the controller servers 125 and 130 in some embodiments to define and deploy traffic groups to allocate additional bandwidth to a machine set. This process will be explained by reference to Figures 5-18 as follows, Figures 5-18 illustrates the interaction of the administrator with the management user interface (UI) 500 for creating and defining traffic groups. In some embodiments, the management server 125 provides this UI and processes the administrator requests made through this UI.
[0056] As shown, the process 400 starts where the management UI 500 (at 405) receives an administrator's request to create a traffic group and creates a traffic group (e.g., creates a traffic group object) in response to this request. Figure 5Illustrates an example of the management UI 500. Specifically, it illustrates the traffic group pane 505 that is displayed when an administrator (i.e., a user) selects the traffic group control 502 in the side panel 507 listing network and security controls 508. The traffic pane 505 includes two tabs, the traffic group pane 504 and the IP prefix list pane 506. In Figure 5 the traffic group pane 504 is shown as having a previously created traffic group estg1, and the user selects the add traffic group control 510 by a cursor click operation, as shown.
[0057] Figure 6 Illustrates the display window 600 that is displayed after the management server 125 selects the add traffic group control 510. It also illustrates that the user provides a name (estg2) for this traffic group in the name field 605 and saves this newly created traffic group by selecting the save control 610 via a cursor click operation. Figure 7 Illustrates adding this newly created traffic group estg2 to the traffic groups listed on the traffic group pane 505.
[0058] After creating (at 405) a traffic group, the process 400 receives a list of network addresses from the user, which will subsequently be associated with the traffic group. In some embodiments, the user can provide a list of addresses before creating the traffic group with which they will later associate it. The process 400 stores the received list of network addresses as an IP prefix list.
[0059] Figures 8-14 Illustrates the interaction of an administrator with the management UI 500 for creating and defining an IP prefix list. Figure 8 Shows the IP prefix list pane 506 including the add IP prefix list control 800, while Figure 9 shows selecting this control 900 by a cursor click operation. Figure 10 Illustrates the display window 1000 that is presented after this selection. It also shows that in the prefix name field 1005, the user has specified a prefix name (espfxl1). It also shows the user's selection of the settings control 1010, which results in Figure 11 the opening of the settings prefix window 1100 shown in
[0060] In the settings prefix window 1100, the user selects the add prefix control 1105, which directs the UI 500 to display Figure 12 the prefix pane 1200 shown inFigure 13 is shown, along with the user's selection of application control 1300 to direct the management server to associate the specified prefix list with a prefix name. Figure 14 illustrates prefix pane 506, which, after selection Figure 13 of application control 1300 in, now displays "1" for the prefix already defined for the prefix name espfxl1. Figure 14 Also shown is the user's selection of save control 1400, which directs the management server to save the specified prefix list espfxl1, which includes a collection of its name and its specified IP prefixes.
[0061] After receiving (at 410) a list of network addresses from the user, process 400 receives from the user a request to associate the received list of network addresses with the traffic group specified at 405. Figures 15-18 illustrates an example of such an association request for some embodiments. Figure 15 illustrates the user's invocation of control set 1500 for the specified traffic group. In some embodiments, the user invokes this control set 1500 by cursor (e.g., right click) operation or keyboard operation on the traffic group name (estg2) displayed in traffic group pane 505.
[0062] Figure 15 Also illustrated is the user's selection of edit control 1505 in control set 1500. This selection results in Figure 16 the display of mapping window 1600. As shown, the mapping window has add mapping control 1605 that allows the user to specify one or more IP prefix mappings to a traffic group (e.g., estg1). Each mapping has a name that can be entered through name field 1610, a gateway name that can be entered through gateway field 1620, and an IP prefix for the mapping that can be entered through prefix drop-down list 1615. To map a traffic group to multiple IP prefixes, in some embodiments, add mapping control 1605 must be invoked multiple times, once for each mapping.
[0063] Figure 16 shows the mapping of traffic group estg1 to prefix list esprfxl1. It also shows that the name for this mapping is esmap1 and the name of the gateway is compute gateway. This name indicates the machine associated with the IP prefix esprfxl1 specified in this example. Figure 17 illustrates the selection of save control 1700 for mapping window 1600 after various values have been specified for traffic group estg1 in the mapping window. Then Figure 18Illustrates the traffic group pane 505 after this save operation. As shown, the traffic group pane 505 shows the attributes of estg1, which now includes the mapping esmap1 to the IP prefix esprfxl1.
[0064] Once a specified traffic group is associated with a list of specified network addresses, the management server 125 directs (at 420) the controller server to deploy a gateway for the traffic group and configure the SDDC router to forward data message traffic for the associated IP prefix of the traffic group through this gateway. In some embodiments, the controller server 130 deploys (at 425) the TG gateway as an HA pair of physical gateways, where one physical gateway serves as the active gateway and the other physical gateway serves as the standby gateway. In some embodiments, each physical gateway is deployed as a machine (e.g., a virtual machine) executing on a host computer in the SDDC, and the gateways in the active / standby pair are deployed on different host computers for HA purposes.
[0065] After deploying the TG gateway, the controller server 130 configures (at 430) the cloud gateway (e.g., gateway 135) to direct all incoming data messages to the VPC of the entity (the incoming data messages are destined for a list of IP addresses of the received traffic group (e.g., destined for the IP prefix of the TG)) to the TG gateway deployed at 425. As mentioned above, the controller server configures the cloud gateway by providing a next-hop forwarding rule that identifies the TG gateway as the next hop for incoming data messages with a destination IP address in the IP prefix.
[0066] Next, at 435, the controller server 130 configures the router implementing the VPC to direct all outgoing data messages leaving the VPC of the entity to the TG gateway deployed at 425, where the outgoing data messages are from a source with a list of IP addresses of the received traffic group (e.g., from the IP prefix of the TG). As mentioned above, the controller server configures the VPC-implementing router by providing next-hop forwarding rules that identify the TG gateway as the next hop for incoming data messages with a source IP address in the IP prefix. After 435, the process ends.
[0067] Many of the above features and applications are implemented as software processes that are specified as a set of instructions recorded on a computer-readable storage medium (also referred to as a computer-readable medium). When these instructions are executed by one or more processing units (e.g., one or more processors, cores of a processor, or other processing units), they cause the (one or more) processing units to perform the actions indicated in the instructions. Examples of computer-readable media include, but are not limited to, CD-ROMs, flash drives, RAM chips, hard disk drives, EPROMs, etc. Computer-readable media do not include carrier waves and electronic signals transmitted wirelessly or by wire connections.
[0068] In this specification, the term "software" is intended to include firmware residing in read-only memory or applications stored on magnetic storage devices that can be read into memory for processing by a processor. Also, in some embodiments, multiple software inventions can be implemented as sub-parts of a larger program while retaining the different software inventions. In some embodiments, multiple software inventions can also be implemented as separate programs. Finally, any combination of separate programs that implement the software inventions described herein is within the scope of the present invention. In some embodiments, a software program, when installed to operate on one or more electronic systems, defines one or more specific machine implementations that run (execute) and perform the operations of the software program.
[0069] Some embodiments include electronic components, such as a microprocessor, that store computer program instructions in a machine-readable or computer-readable medium (alternatively referred to as a computer-readable storage medium, machine-readable medium, or machine-readable storage medium). Some examples of such computer-readable media include RAM, ROM, compact discs read-only (CD-ROM), recordable compact discs (CD-R), rewritable compact discs (CD-RW), digital versatile discs read-only (e.g., DVD-ROM, dual-layer DVD-ROM), various recordable / rewritable DVDs (e.g., DVD-RAM, DVD-RW, DVD+RW, etc.), flash memory (e.g., SD cards, mini-SD cards, micro-SD cards, etc.), magnetic and / or solid state disk drives, read-only and recordable Blu- ray discs, ultra density optical discs, any other optical or magnetic medium, and floppy disks. The computer-readable medium can store a computer program executable by at least one processing unit and including a set of instructions for performing various operations. Examples of computer programs or computer code include machine code (e.g., generated by a compiler), and files including high-level code that is executed by a computer, electronic component, or microprocessor using an interpreter.
[0070] While the foregoing discussion has mainly referred to a microprocessor or multi-core processor that executes software, some embodiments are executed by one or more integrated circuits, such as application-specific integrated circuits (ASICs) or field-programmable gate arrays (FPGAs). In some embodiments, such integrated circuits execute instructions stored on the circuit itself.
[0071] As used in this specification, the terms "computer", "server", "processor", and "memory" all refer to electronic or other technical devices. These terms do not include a person or a group of people. For the purposes of this specification, the term "display" means display on an electronic device. As used in this specification, the terms "computer-readable medium", "computer-readable medium", and "machine-readable medium" are entirely limited to tangible physical objects that store information in a computer-readable form. These terms do not include any wireless signals, wired download signals, and any other transient or ephemeral signals.
[0072] Figure 19 Conceptual diagram illustrates a computer system 1900 in which some embodiments of the present invention are implemented. The computer system 1900 can be used to implement any one of the above-mentioned host, controller, and manager. Accordingly, it can be used to execute any of the above processes. This computer system includes various types of non-transitory machine-readable media and interfaces for various other types of machine-readable media. The computer system 1900 includes a bus 1905, one or more processing units 1910, a system memory 1925, a read-only memory 1930, a permanent storage device 1935, an input device 1940, and an output device 1945.
[0073] The bus 1905 collectively represents all systems, peripheral devices, and chipset buses that communicatively connect the numerous internal devices of the computer system 1900. For example, the bus 1905 communicatively connects one or more processing units 1910 to the read-only memory 1930, the system memory 1925, and the permanent storage device 1935.
[0074] From these various memory units, one or more processing units 1910 retrieve the instructions to be executed and the data to be processed in order to execute the processes of the present invention. In different embodiments, one or more processing units can be a single processor or a multi-core processor. The read-only memory (ROM) 1930 stores static data and instructions required by one or more processing units 1910 and other modules of the computer system. On the other hand, the permanent storage device 1935 is a read-write memory device. This device is a non-volatile memory unit that stores instructions and data even when the computer system 1900 is turned off. Some embodiments of the present invention use a mass storage device, such as a magnetic disk or an optical disk and its corresponding disk drive, as the permanent storage device 1935.
[0075] Other embodiments use a removable storage device (such as a floppy disk, flash drive, etc.) as the permanent storage device. Like the permanent storage device 1935, the system memory 1925 is a read-write memory device. However, unlike the storage device 1935, the system memory is a volatile read-write memory, such as random access memory. The system memory stores some of the instructions and data that the processor needs during operation. In some embodiments, the processes of the present invention are stored in the system memory 1925, the permanent storage device 1935, and / or the read-only memory 1930. From these various memory units, the (one or more) processing units 1910 retrieve the instructions to be executed and the data to be processed in order to execute the processes of some embodiments.
[0076] The bus 1905 is also connected to input and output devices 1940 and 1945. The input device enables the user to convey information and selection requests to the computer system. The input device 1940 includes an alphanumeric keyboard and a pointing device (also known as a "cursor control device"). The output device 1945 displays the images generated by the computer system. The output device includes a printer and a display device, such as a cathode ray tube (CRT) or a liquid crystal display (LCD). Some embodiments include a device that serves as both an input and an output device, such as a touch screen.
[0077] Finally, as Figure 19 shown, the bus 1905 also couples the computer system 1900 to a network 1965 through a network adapter (not shown). In this way, the computer can be part of a network of computers (such as a local area network ("LAN"), a wide area network ("WAN"), or an intranet) or a network of networks (such as the Internet). Any or all components of the computer system 1900 can be used in conjunction with the present invention.
[0078] Although the present invention has been described with reference to many specific details, those of ordinary skill in the art will recognize that the present invention can be embodied in other specific forms without departing from the spirit of the present invention. For example, some of the above embodiments allocate more bandwidth to a set of data message flows by having an administrator request the creation of a new traffic group, associating a set of network addresses with this traffic group, and then deploying a new gateway for this traffic group to handle the ingress / egress traffic associated with this set of network addresses. However, other embodiments have the administrator simply request a specific amount (e.g., a specific number of bytes / second) or a general amount (e.g., high, medium, low, etc.) of ingress / egress bandwidth for a set of data message flows. Accordingly, those of ordinary skill in the art will understand that the present invention is not limited by the foregoing illustrative details, but rather is defined by the appended claims.
Claims
1. A method for deploying an edge forwarding element in a software-defined data center (SDDC), the method comprising: Deploying a default first edge forwarding element for an entity to handle data message flows between machines in a first network of the SDDC and machines outside the first network of the SDDC; Receiving a request to allocate more bandwidth to a first set of data message flows entering or leaving the first network of the SDDC; Deploying a second edge forwarding element for the entity to handle the first set of data message flows so as to allocate more bandwidth to the first set of data message flows, while continuing to handle a second set of data message flows through the default first edge node, and configuring a set of forwarding elements in the first network to forward data message flows in the first set of data message flows from a set of machines in the first network to the second edge forwarding element.
2. The method according to claim 1, wherein receiving the request comprises: Receiving a request to create a traffic group; And Receiving a list of network addresses associated with the traffic group, the list of network addresses identifying a subset of data message flows to be handled by the second edge node.
3. The method according to claim 2, wherein receiving the list of network addresses associated with the traffic group comprises: Receiving a prefix of a network address; And Receiving a request to associate the prefix of the network address with the traffic group.
4. The method according to claim 3, further comprising creating an association between the traffic group and the received prefix of the network address.
5. The method according to claim 2, wherein the network address is a network address associated with an interface of a forwarding element for connecting a machine in the first network to the first network.
6. The method according to claim 1, wherein deploying the second edge forwarding element comprises: Configuring the second edge forwarding element to forward a first set of data messages to a forwarding element in an external network.
7. The method according to claim 6, wherein The edge forwarding element is an edge router, and Configuring the second edge forwarding element comprises configuring the second edge forwarding element to announce a route to the set of machines to a forwarding element in an external network.
8. The method according to claim 6, wherein The set of forwarding elements comprises a set of intermediate routers, and Configuring the set of forwarding elements comprises providing a next-hop forwarding rule to the set of intermediate routers.
9. The method according to claim 6, wherein The set of forwarding elements comprises a set of intermediate switches implementing a logical switch, and Configuring the set of forwarding elements comprises providing a forwarding rule to the set of intermediate switches to direct the corresponding intermediate switches to forward a first set of data messages to the second edge forwarding element through a set of tunnels, the set of tunnels connecting the set of intermediate switches to the second edge forwarding element.
10. The method according to claim 6, wherein configuring the set of forwarding elements in the first network includes configuring the set of forwarding elements to forward a data message flow having (i) a destination IP address associated with the second edge forwarding element and (ii) a source IP address associated with the set of machines to the second edge forwarding element.
11. The method according to claim 6, further comprising configuring the gateway of the SDDC to forward a data message flow having a destination IP address associated with the set of machines to the second edge forwarding element.
12. The method according to claim 1, wherein the SDDC is a public cloud data center having a second network, the first network is a private network defined in the second network to implement a virtual private cloud (VPC) for the entities in the public cloud data center, and deploying the second edge forwarding element includes: deploying a gateway in the public cloud data center; and configuring a set of forwarding elements in the second network to forward a first set of data message flows to the deployed gateway.
13. The method according to claim 1, wherein deploying the first edge forwarding element and the second edge forwarding element includes deploying the first edge forwarding element and the second edge forwarding element as different devices in the SDDC.
14. The method according to claim 13, wherein the different devices are a first host computer and a second host computer on which the first edge forwarding element and the second edge forwarding element execute.
15. The method according to claim 1, further comprising: receiving a request to allocate more bandwidth to a third set of data message flows entering or leaving the first network of the SDDC; deploying a third edge forwarding element for the entity to process the third set of data message flows in order to allocate more bandwidth to the third set of data message flows, while continuing to process the second set of data message flows through the default first edge node and the first set of data message flows through the second edge node.
16. The method according to claim 15, wherein deploying the second edge forwarding element and the third edge forwarding element includes deploying the second edge forwarding element and the third edge forwarding element to execute on different devices in the SDDC.
17. The method according to claim 16, wherein the different devices are a first host computer and a second host computer on which the first edge forwarding element and the third edge forwarding element execute, and the different host computers allow different physical network interface cards (PNICs) to be used for the first set and the third set of data message flows.
18. The method according to claim 16, wherein the different devices are a first gateway device and a second gateway device.
19. A method for providing bandwidth as a resource in a software-defined data center (SDDC), the method comprising: providing, via a user interface, a first set of controls to define traffic groups, and deploying dedicated edge forwarding elements for the traffic groups to process a first set of data message flows associated with the traffic groups; Provide a second set of controls via a user interface to define a set of network addresses associated with the traffic group within the SDDC, the set of network addresses serving as a source network address or a destination network address for a first set of data message flows associated with the traffic group; Deploy the dedicated edge forwarding element to process the first set of data message flows to allocate more bandwidth for the first set of data message flows, and configure a set of forwarding elements in a first network of the SDDC to forward data message flows in the first set of data message flows from a set of machines in the first network to the dedicated edge forwarding element.
20. The method of claim 19, further comprising deploying a default edge forwarding element to process a second set of data message flows not associated with the traffic group.
21. The method of claim 19, wherein the second set of controls includes a subset of controls for receiving a prefix of a network address and for receiving a request to associate the prefix of the network address with the traffic group.
22. The method of claim 21, further comprising creating an association between the traffic group and the prefix of the received network address.
23. The method of claim 21, wherein the set of network addresses is a set of network addresses associated with an interface of a set of forwarding elements that connect a set of machines in a first network of the SDDC to the first network, the set of machines serving as a source or a destination for the first set of data message flows.
24. The method of claim 19, wherein deploying the dedicated edge forwarding element includes: Configuring the dedicated edge forwarding element to forward a first set of data messages to a forwarding element associated with the set of network addresses in a network external to the first network.
25. The method of claim 24, wherein The edge forwarding element is an edge router, and Configuring the dedicated edge forwarding element includes configuring the dedicated edge forwarding element to advertise a route associated with the set of network addresses to a forwarding element in an external network.
26. The method of claim 24, wherein The set of forwarding elements includes a set of intermediate routers, and Configuring the set of forwarding elements includes providing a next-hop forwarding rule to the set of intermediate routers.
27. The method of claim 24, wherein The set of forwarding elements includes a set of intermediate switches implementing a logical switch, and Configuring the set of forwarding elements includes providing a forwarding rule to the set of intermediate switches to direct the corresponding intermediate switches to forward a first set of data messages through a set of tunnels that connect the set of intermediate switches to a second edge forwarding element.
28. The method of claim 24, further comprising configuring a gateway of the SDDC to forward a data message flow having a destination IP address in the set of network addresses to the dedicated edge forwarding element.
29. A machine-readable medium storing a program which, when implemented by at least one processing unit, implements the method according to any one of claims 1-28.
30. An electronic device, comprising: a set of processing units; and a machine-readable medium storing a program which, when implemented by at least one of the processing units, implements the method according to any one of claims 1-28.
31. A system for data communication, comprising means for implementing the method according to any one of claims 1-28.
32. A computer program product comprising instructions which, when executed by a computer, cause the computer to execute the method according to any one of claims 1-28.
Citation Information
Patent Citations
Dynamic scaling of virtual private network connections
US20190327112A1