Link Layer Method for Configuring Bare Metal Servers in a Virtual Network
By extending LLDP to configure virtual network ports that map physical servers in virtual networks, the solution addresses the challenges of maintaining privacy, isolation, and security while achieving scalable and secure connectivity in virtual private clouds.
Patent Information
- Application Number
- JP2022502257
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-07-18
- Filing Date
- 2020-07-15
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2040-07-15
AI Technical Summary
Existing methods for connecting physical servers to virtual networks, especially in virtual private clouds (VPCs), face challenges in maintaining privacy, isolation, and security, while also dealing with scalability and vendor lock-in issues.
The solution involves extending the Link Layer Discovery Protocol (LLDP) to support the configuration of virtual network ports that map physical servers in a virtual network, using extended Type-Length-Value (TLV) elements to transmit virtual network settings to a fortified network interface, allowing for secure and scalable packet transfer between physical servers and virtual network nodes.
This approach enables secure and scalable connectivity of physical servers to virtual networks, maintaining client privacy and control while avoiding vendor lock-in and supporting high scalability, thus enhancing the overall virtual network architecture.
Smart Images

Figure 0007696329000001 
Figure 0007696329000002 
Figure 0007696329000003
Abstract
Description
Technical Field
[0001] In some embodiments, the present invention relates to configuring virtual network ports that map physical servers in a virtual network, and more specifically, but not exclusively, to extending the Link Layer Discovery Protocol (LLDP) to support the configuration of virtual network ports that map physical servers in a virtual network.
Background Art
[0002] For example, the ever-increasing scale of networks in data centers, cloud services, or the like, or combinations thereof, has led to a heavy reliance on virtual networking to provide an abstraction layer across one or more networks to facilitate complete software control of the network, thereby enabling a simple and highly scalable network routing structure. In fact, the ability to virtualize networks, workloads, and applications and then move them across the network infrastructure gave rise to the first cloud architectures.
[0003] Applying virtual networking, logical networks that are completely decoupled from physical servers can be quickly and easily constructed to adjust workloads across the logical space. In this way, virtual networks can extend beyond the boundaries of physical networks. Virtual networking is further beneficial in terms of flexibility, isolation, and automation facilitated by software-based management of the network.
[0004] Virtual networking fundamentally facilitates data communication among a plurality of virtualized components in a computing environment, such as a virtual private cloud (VPC) operated by a VPC provider to provide services to one or more clients. Such virtualized components (nodes) may include virtual machines (VMs), containers, unikernels, or the like, or combinations thereof.
[0005] However, while virtual networking is primarily directed at providing network abstraction for virtualized nodes, in some deployments, one or more physical servers may also be included in the VPC by connecting to the virtual network. Such physical servers, specifically bare-metal servers owned by clients deployed as part of the VPC, are configured to be run under the complete control of the client to ensure the privacy, isolation, and security of the client-owned physical servers. SUMMARY OF THE INVENTION
[0006] According to a first aspect of the present invention, a method for configuring a virtual port for a physical server to support packet transfer between the physical server and other network nodes on a virtual network, the method comprising using one or more processors to transmit one or more configuration protocol data units (PDUs) of an extended link layer data protocol (LLDP) to a network interface card (NIC) of the physical server connected to the network, wherein one or more of the configuration PDUs comprise one or more extended type length value (TLV) that define one or more virtual network settings for a virtual network port that maps the physical server in the virtual network. The NIC is configured to deploy a virtual network port to support packet exchange between the physical server and one or more of a plurality of nodes of the virtual network by processing transmitted and received packets by one or more virtual network virtualization protocols using one or more of the virtual network settings.
[0007] According to a second aspect of the present invention, there is provided a system for configuring a virtual port for a physical server to support packet transfer between the physical server and other network nodes on a virtual network, the system comprising one or more processors for executing code. The code comprises code instructions for transmitting one or more configuration protocol data units (PDUs) of an extended link layer data protocol (LLDP) to a network interface card (NIC) of a physical server connected to the network. One or more of the configuration PDUs comprise one or more extended type-length-values (TLVs) defining one or more virtual network settings for a virtual network port that maps the physical server in the virtual network. The NIC is configured to deploy a virtual network port to support packet exchange between the physical server and one or more of a plurality of nodes of the virtual network by processing transmitted and received packets by means of one or more virtual network virtualization protocols using one or more of the virtual network settings.
[0008] According to a third aspect of the present invention, there is provided a computer program product for configuring a virtual port for a physical server to support packet transfer between the physical server and other network nodes on a virtual network, the computer program product comprising a non-transitory computer-readable storage medium and first program instructions for transmitting one or more configured PDUs of an extended LLDP to a NIC of a physical server connected to a network. One or more of the configured PDUs comprise one or more extended TLVs that define one or more virtual network settings for a virtual network port that maps the physical server in the virtual network. The NIC is configured to deploy a virtual network port to support packet exchange between the physical server and one or more of a plurality of nodes of the virtual network by processing outgoing and incoming packets by one or more virtual network virtualization protocols using one or more of the virtual network settings. The first program instructions are executed by one or more processors from the non-transitory computer-readable storage medium.
[0009] In a further embodiment of the first aspect, the second aspect, or the third aspect, or a combination thereof, the virtual network is at least a part of a virtual private cloud (VPC).
[0010] In a further embodiment of the first aspect, the second aspect, or the third aspect, or a combination thereof, the physical server is a bare metal server deployed as part of a VPC.
[0011] In a further embodiment of the first, second, or third aspect, or a combination thereof, the virtual network virtualization protocol comprises one or more virtual network encapsulation protocols. The virtual network port supports packet exchange by encapsulating and decapsulating outgoing and incoming packets by one or more of the virtual network encapsulation protocols using one or more of the virtual network settings.
[0012] In a further embodiment of the first, second, or third aspect, or a combination thereof, the virtual network virtualization protocol comprises one or more members of a group consisting of Virtual Extensible Local Area Network (VXLAN), Network Virtualization using Generic Routing Encapsulation (NVGRE), Generic Network Virtualization Encapsulation (GENEVE), or Stateless Transport Tunneling (STT), or a combination thereof.
[0013] In a further embodiment of the first, second, or third aspect, or a combination thereof, one or more of the configuration PDUs are defined by the extended Data Center Bridging Exchange (DCBX) of LLDP. The extended DCBX is extended to support one or more of the extended TLVs.
[0014] In a further embodiment of the first, second, or third aspect, or a combination thereof, the virtual network configuration comprises one or more members of a group consisting of a virtual network address assigned to a virtual network port deployed to map a network port of a physical server within a range of virtual addresses of the virtual network, a virtual network identifier (VNID) of the virtual network, a VPC identifier (VPC ID), a security group association for the physical server, and a multicast group association for the physical server.
[0015] In a further embodiment of the first, second, or third aspect, or a combination thereof, the virtual network address defines an Internet Protocol (IP) address assigned to a virtual network port deployed at a NIC within a range of IP addresses of the virtual network.
[0016] In an optional embodiment of the first, second, or third aspect, or a combination thereof, the virtual network address defines a Media Access Control (MAC) address assigned to the virtual network port, and the virtual network port applies the IP address and the MAC address for encapsulation and decapsulation.
[0017] In a further embodiment of the first, second, or third aspect, or a combination thereof, each of the packets exchanged between a NIC of the physical server and one or more of the nodes of the virtual network is a member of a group consisting of unicast packets, multicast packets, and broadcast packets.
[0018] Other systems, methods, features, and advantages of the present disclosure will be apparent to, or will become apparent to, those of ordinary skill in the art upon examination of the following detailed description, taken in conjunction with the accompanying drawings. All such additional systems, methods, features, and advantages are intended to be included within the scope of this description, within the scope of the present disclosure, and protected by the accompanying claims.
[0019] Unless otherwise defined, all technical and scientific terms used herein, or both, have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. Although methods and materials similar or equivalent to those described herein can be used in the practice or testing of embodiments of the present invention, exemplary methods and materials, or both, are described below. In case of conflict, the present patent specification, including definitions, will control. Further, the materials, methods, and examples are illustrative only and not intended to be limiting.
[0020] The implementation of the methods or systems, or both, of embodiments of the present invention can include performing, or completing, selected tasks manually, automatically, or a combination of both. Further, depending on the actual instrumentation and equipment of the methods or systems, or both, of embodiments of the present invention, some selected tasks can be implemented by hardware, by software, by firmware, or by a combination thereof, using an operating system.
[0021] For example, the hardware for performing a selected task according to an embodiment of the present invention can be implemented as a chip or a circuit. As software, a selected task according to an embodiment of the present invention can be implemented as a plurality of software instructions executed by a computer using any suitable operating system. In an exemplary embodiment of the present invention, one or more tasks according to an exemplary embodiment of the method or system described herein, or both, are executed by a data processor such as a computing platform for executing a plurality of instructions. Optionally, the data processor includes volatile memory for storing instructions or data, or both, or non-volatile memory for storing instructions or data, or both, such as, for example, a magnetic hard disk or a removable medium, or both. Optionally, a network connection is also provided. A display, or a user input device such as a keyboard or a mouse, or both, are also optionally provided.
[0022] Some embodiments of the present invention are described herein by way of example only with reference to the accompanying drawings. Next, with particular reference to the drawings in detail, it is emphasized that the details shown are illustrative and for the purpose of an exemplary description of embodiments of the present invention. In this regard, the description, understood in conjunction with the drawings, will make apparent to those skilled in the art how embodiments of the present invention may be implemented.
Brief Description of the Drawings
[0023]
Figure 1
Figure 2
Figure 3
Figure 4A
Figure 4B
[0024] In some embodiments, the present invention relates to configuring a virtual network port that maps a physical server in a virtual network, and more specifically, but not exclusively, to extending the network LLDP protocol to support the configuration of a virtual network port that maps a physical server in a virtual network.
[0025] According to some embodiments of the present invention, there are provided a method, a system, and a computer program product for configuring a virtual network port deployed to map a physical server in a virtual network to support the exchange of data packets between the physical server and one or more of a plurality of network nodes of the virtual network. The configuration of the virtual network port is performed using one or more link layer configuration protocols extended to support the distribution of virtual network settings assigned to the virtual network port. Such link layer configuration protocols may include, for example, the Link Layer Discovery Protocol (LLDP), the Data Center Bridging Capabilities Exchange Protocol (DCBX) which is an extension of the LLDP protocol, or the like, or combinations thereof.
[0026] A virtual network, such as a software-defined network (SDN), may provide a logical network abstraction across a physical network to connect a plurality of network nodes that may include, for example, virtual machines, virtual routers, virtual router interfaces, physical hosts mapped via virtual endpoints, physical routers mapped via virtual endpoints, containers, unikernels, one or more virtual resources or hardware resources, or virtual interfaces that map both, or the like, or combinations thereof. The virtual network may constitute at least a part of a virtual private cloud (VPC) operated by a VPC provider to provide services to one or more clients.
[0027] The network nodes of a virtual network apply one or more of a plurality of virtual network virtualization protocols, or virtual network tunneling protocols, or both, for constructing and using a virtual domain across the virtual network. For example, the network nodes may use one or more virtual network encapsulation protocols, such as Virtual Extensible LAN (VXLAN), Network Virtualization using Generic Routing Encapsulation (NVGRE), Generic Network Virtualization Encapsulation (GENEVE), Stateless Transport Tunneling (STT), or the like, or a combination thereof, to exchange data packets among the network nodes.
[0028] A physical server, specifically, a bare-metal server owned by a client that may be deployed as part of a VPC, should not normally execute VPC provider software components to ensure the privacy, isolation, and security of the physical server owned by the client. Since the VPC provider software components should not be executed by the physical server, in particular, for implementing virtual network connections, the physical server cannot directly communicate with network nodes on the virtual network defined by the VPC using virtual network virtualization protocols.
[0029] Therefore, a virtual network port may be developed to map a physical server in a virtual network and support the transmission of data packets (e.g., unicast packets, multicast packets, or broadcast packets, or a combination thereof) from the physical server to a virtual network node, or the reception of packets from a virtual network node in the physical server, or both. For this purpose, the virtual network port may encapsulate egress packets (egress traffic) transmitted from the physical server by a virtual network encapsulation protocol used by the virtual network node. On the ingress path, the virtual network port may decapsulate ingress packets received from one or more of the virtual network nodes destined for the physical server.
[0030] However, since the privacy, isolation, and security of the physical server owned by the client should not be jeopardized by running the VPC provider software components, the virtual network port should not be deployed on the physical server itself, specifically, not in the execution environment of the physical server that provides services to the client.
[0031] To enable the connection of the physical server to the virtual network while maintaining the privacy of the client's execution environment, the virtual network port may be deployed in one or more network circuits that connect the physical server to the network in which the virtual network is deployed. Specifically, the virtual network port may be deployed in a network interface, e.g., a network interface controller (NIC) of the physical server that connects the physical server to a switch. In particular, the network interface of the physical server may be an enhanced network interface with sufficient processing resources and memory resources to implement the virtual network port.
[0032] To process packets exchanged between a physical server and a virtual network node by a virtual network virtualization protocol or a virtual network tunneling protocol or both used by the virtual network node, the virtual network port must apply one or more virtual network settings that are specific to the virtual network and uniquely identify the virtual network port. These network settings may include, for example, a virtual network identifier (VNID), a VPC identifier (VPC ID), an Internet Protocol (IP) address assigned to the virtual network port within a range of IP addresses defined for the virtual network, a Media Access Control (MAC) assigned to the virtual network port that is unique within the virtual network, a security group (SG) association of the physical server in the virtual network, or the like, or a combination thereof.
[0033] The virtual network ports deployed to connect a physical server to a virtual network are not inherently controlled by one or more virtual network controllers, such as an SDN controller, or the like, or a combination thereof, that are deployed and executed to configure, control, manage, or monitor the virtual network, or a combination thereof. This is because, as described herein, a VPC provider should not deploy software components on a physical server because such software components may inadvertently or intentionally violate a client's privacy, security, and isolation, or a combination thereof. Therefore, the virtual network controller needs to send virtual network settings to the virtual network port.
[0034] Furthermore, in some deployments of physical servers in a VPC, the virtual network controller may not be able to manage the network interfaces of the physical servers using high-level network management protocols such as Simple Network Management Protocol (SNMP), Network Configuration Protocol (NETCONF), and the like, or combinations thereof. To support high scalability (to support a large number of virtual network ports), reduce complexity, support legacy networking equipment, or a combination thereof, the virtual network controller may send a virtual network configuration that implements virtual network ports using one or more link layer configuration protocols, such as LLDP, DCBX, or the like, or combinations thereof, to the enhanced network interface of the physical server. Such link layer configuration protocols are commonly used in most network infrastructures, if not all, and are therefore supported by most of the existing networking equipment, including the enhanced network interface of the physical server.
[0035] In particular, the link layer configuration protocol may be extended to support the delivery of virtual network configurations to virtual network ports. For example, one or more Type Length Value (TLV) elements may be added to the link layer configuration protocol to enable the delivery of virtual network configurations from the virtual network controller to the physical server, specifically, to the enhanced network interface of the physical server.
[0036] A virtual network controller may transmit one or more of the extended TLVs that encode, or define, or both, the virtual network settings assigned to a virtual network port to map a physical server in a virtual network. A fortified network interface configured to support extended TLVs may extract the virtual network settings from the extended TLVs and apply the virtual network settings to deploy a virtual network port.
[0037] After being properly deployed, the virtual network port may process outgoing and incoming packets by a virtual network virtualization protocol or a virtual network tunneling protocol, or both, used in the virtual network using the virtual network settings assigned to the virtual network port. For example, the virtual network port may encapsulate an outgoing packet and decapsulate an incoming packet by a virtual network encapsulation protocol using the virtual network settings assigned to the virtual network port, respectively.
[0038] Configuring and deploying a virtual network port in a fortified network interface of a physical server to map the physical server in a virtual network may provide significant advantages compared to current, existing methods and systems for connecting a physical server to a virtual network.
[0039] Connecting a physical server, especially a bare metal server owned by a client, to a virtual network, for example, connecting a bare metal server under the complete control of a client to a VPC operated by a VPC provider to provide services to the client, is highly desirable and may be essential for multiple applications in many cases.
[0040] Some of the existing methods for connecting a physical server to a virtual network may include deploying a virtualization layer on the physical server to equip it with virtual network components (e.g., virtual switches) owned and controlled by a provider of the virtual network, i.e., a VPC provider, and exposing a single virtual server to the client instead of the physical server owned by the client. This solution is simple and very well aligned with the virtual network architecture applied in a VPC that views the physical server, therefore, in the same way as any other virtual node. However, this approach may thus expose the physical server service owned by the client, which is provided to a client that does not fully control the execution environment of the physical server, to significant risks. In contrast, deploying virtual network ports in an enhanced network interface of the physical server that maintains a completely separate execution environment will, therefore, neither affect, expose to risk, or result in a combination of affecting, exposing to risk, or affecting the execution environment of the physical server that is under the full control of the client (a single tenant).
[0041] Other existing methods may involve deploying virtual network ports in an enhanced network interface (Smart NIC) of a physical server, where the Smart NIC has a complete execution environment of its own (processor, memory resources, connection to the control network) that is completely controlled by the provider of the virtual network, i.e., the VPC provider, via a control interface that is invisible to the client. Also, this solution may be very well aligned with the virtual network architecture applied in the VPC. However, this approach may bring significant limitations. First, configuring or managing the switch, or both, needs to be in the physical network domain rather than the virtual network domain, and thus may break the virtual network architecture. Furthermore, the implementation of deploying virtual network ports in the switch may be specific to each switch vendor, and thus may bring significant scalability limitations and vendor lock-in limitations. Additionally, to support (remote) control via the Smart NIC, the Smart NIC may be highly complex and thus may be costly in terms of development or manufacturing, or both. On the other hand, the virtual network ports deployed on the enhanced network interface of the physical server according to the present invention are configured using standard, commonly used network link layer configuration protocols (e.g., LLDP, DCBX) extended to support the distribution of virtual network settings for the enhanced network interface of the physical server. These link layer configuration protocols are inherently extensible, and thus the effort to extend the configuration and, optionally, with extended response objects is minimal. Since standard networking equipment, such as the enhanced network interface of the physical server, inherently supports these link layer configuration protocols, no special capabilities, features, or functions, or combinations thereof, need to be implemented in the enhanced network interface, thus significantly simplifying it and reducing costs.
[0042] Using a link layer configuration protocol to distribute virtual network settings to an enhanced network interface can be more beneficial in a number of common, widespread virtual network or VPC deployments, or both, where the physical server cannot be remotely managed using one or more higher level network management protocols such as, for example, SNMP, NETCONF, or the like, or combinations thereof. While it may not be possible to access the physical server using a network management protocol, the physical server, particularly its enhanced network interface, is natively accessible using low level link layer configuration protocols such as LLDP and DCBX. These low level link layer configuration protocols form a fundamental and essential part of network configuration, network control, or network management, or combinations thereof, without which the network may not be properly deployed. Therefore, the enhanced network interface must support the configuration PDUs of one or more of these link layer configuration protocols and respond to such configuration PDUs.
[0043] Other existing methods may include deploying virtual network ports in switches that connect physical servers to a network. This solution can sometimes be very easy to apply since existing switches can usually support virtual network ports. Also, this solution is completely transparent to the client (a single tenant), i.e., to the physical server hosting a single tenant, thus ensuring complete privacy, isolation, and security for the client. However, this approach can have significant limitations. First, the switch needs to be configured, or managed, or both, in the physical network domain rather than in the virtual network domain, thus breaking the virtual network architecture. Further, the implementation of deploying virtual network ports in switches can be specific to each switch vendor, which can thereby result in significant scalability limitations and vendor lock-in limitations. This is in contrast to the deployment of virtual network ports on enhanced network interfaces on the physical server side. Therefore, the scalability is greatly enhanced and vendor lock-in is avoided because the virtual network ports are deployed on the physical server side, thereby being independent and having no dependency on the switch, and thereby enabling the use of substantially any switch from any vendor that can be used to deploy virtual network ports.
[0044] Before explaining in detail at least one embodiment of the present invention, it should be understood that the present invention is not necessarily limited to the details of construction and the arrangements of components or methods, or both, described in the following description, or illustrated in the drawings or examples, or a combination thereof. The present invention is capable of other embodiments or of being practiced or carried out in various ways.
[0045] As will be appreciated by one skilled in the art, aspects of the present invention may be implemented as a system, method or computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a "circuit", "module" or "system". Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable media having computer readable program code embodied thereon.
[0046] Any combination of one or more computer-readable media may be utilized. A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, an electronic system, a magnetic system, an optical system, an electromagnetic system, an infrared system, or a semiconductor system, an electronic device, a magnetic device, an optical device, an electromagnetic device, an infrared device, or a semiconductor device, or any suitable combination of the foregoing, but is not limited thereto. More specific examples (non-exhaustive list) of computer-readable storage media include, hereinafter, namely, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this specification, a computer-readable storage medium may be any tangible medium that can include or store a program for use by or in connection with an instruction execution system, an instruction execution device, or an instruction execution apparatus.
[0047] A computer-readable signal medium may include a propagated data signal in which a computer-readable program code is embodied, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium is any computer-readable medium that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device, rather than a computer-readable storage medium.
[0048] Computer program code embodied with computer-readable program instructions on a computer-readable medium may be transmitted using any appropriate medium, including wireless, wireline, fiber optic cable, RF, or the like, or any suitable combination of the foregoing.
[0049] The program code for performing the operations for aspects of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java(R), Smalltalk, C++, or the like, and conventional programming languages such as the "C" programming language or similar programming languages.
[0050] The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or a remote server. In a scenario where it is executed entirely on a remote computer or a remote server, the remote computer may be connected to the user's computer via any type of network including a Local Area Network (LAN) or a Wide Area Network (WAN), or the connection may be made to an external computer (e.g., via the Internet using an Internet Service Provider). The program code may be downloaded from a computer-readable storage medium to each computing device or processing device, or both, or to an external computer or an external storage device via a network such as the Internet, a Local Area Network, a Wide Area Network, or a wireless network, or a combination thereof.
[0051] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0052] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible examples of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions that comprises one or more executable instructions for implementing the specified logical function. In some alternative embodiments, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It should also be noted that each block of the block diagrams or flowchart diagrams, or combinations of blocks in the block diagrams or flowchart diagrams, can be implemented by a dedicated hardware-based system that performs the specified function or operation, or combinations of dedicated hardware and computer instructions.
[0053] Referring now to FIG. 1, FIG. 1 presents a flowchart illustrating an exemplary process for transferring virtual network settings to a virtual network port that maps a physical server in a virtual network to support packet transfer between the physical server and a node connected to the virtual network, according to some embodiments of the present invention.
[0054] Exemplary processes 110, 120, and 130 may be executed to transfer one or more virtual network configurations to a virtual network port 104 deployed to map physical servers in a software-defined network (SDN) that provides logical network abstraction across a virtual network, e.g., a physical network. The virtual network port 104 is deployed to support packet transfer between a physical server and one or more network nodes connected to the virtual network by encapsulating and decapsulating outgoing and incoming packets, e.g., by one or more virtual network encapsulation protocols applied by network nodes of the virtual network, such as VXLAN, NVGRE, GENEVE, STT, or the like, or combinations thereof.
[0055] The virtual network may comprise at least a portion of a virtual private cloud (VPC) (which may span across multiple virtual networks) comprising a plurality of network nodes that apply one or more virtual network virtualization protocols or virtual network tunneling protocols, or both, to exchange data packets with each other. A physical server, e.g., a single-tenant bare-metal server, may be deployed as part of the VPC. However, a physical server, specifically a bare-metal server, may not have any virtualization layer and thus may not be able to connect directly to the virtual network to communicate with virtual network nodes that use virtual network virtualization protocols.
[0056] Process 110 may be executed, for example, by virtual network controller 102 to transfer to a physical server the virtual network settings assigned for virtual network port 104, such as VNID, VPC ID, IP address, MAC address, physical server security group (SG) association, or the like, or a combination thereof. Instead of directly transferring the virtual network settings to the physical server, virtual network controller 102 typically communicates with one or more link layer agents deployed in the network. Virtual network controller 102 may transfer the virtual network settings to the link layer agents using one or more higher level protocols, such as network management protocols (e.g., SNMP, NETCONF, etc.).
[0057] Process 120 may be executed, for example, by one or more of the link layer agents deployed in one or more of the physical network nodes in a switch, specifically, an edge switch that connects the physical server to the network. The link layer agent may be configured to support one or more network link layer configuration protocols, such as LLDP, or the like, or a combination thereof, extended to support the delivery of virtual network settings. In particular, the LLDP protocol is extended to include one or more extended TLVs added to extend the LLDP protocol for the delivery of virtual network settings. Accordingly, the link layer agent may create one or more LLDP configuration PDUs comprising the virtual network settings received from virtual network controller 102 and transmit the LLDP configuration PDUs to the physical server.
[0058] Process 130 may be executed, implemented, or realized on an enhanced network interface of a physical server, or may be executed by a virtual network port 104 where such execution, implementation, realization, or combinations thereof occur. The virtual network port 104 is configured to support receiving, decoding, or processing, or combinations thereof, of extended TLVs added to the LLDP protocol to define a virtual network configuration. Thus, the virtual network port 104 may receive one or more extended TLVs from the network controller 102 and may further apply the virtual network configuration extracted from the received extended TLVs.
[0059] After receiving the virtual network configuration, the virtual network port 104 may exchange packets between the physical server and one or more of the network nodes of the virtual network using one or more virtual network virtualization protocols or virtual network tunneling protocols, or both. In particular, the virtual network port 104 may encapsulate packets transmitted from the physical server to the virtual network node and may decapsulate packets received from the virtual network node directed to the physical server.
[0060] Reference is also made to FIG. 2, which is a schematic diagram of an exemplary system for transferring a virtual network configuration to a virtual network port that maps a physical server in a virtual network to support packet transfer between the physical server and a node connected to the virtual network, according to some embodiments of the present invention.
[0061] The exemplary networked system 200 may include a physical server 202 connected via a switch 206 to a network 210, such as, for example, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), or the like, or a combination thereof. The physical server 202 may be connected to the switch 206 using a network interface 220, such as, for example, a NIC or the like, or a combination thereof, that supports connections to one or more networks. The network interface 220 may be an enhanced network interface 220, such as, for example, a smart NIC, that includes one or more processors and memory resources for a program store or data store.
[0062] A virtual network 212 provides logical network abstraction across the physical network 210. In particular, the network 210 may be part of a data center infrastructure that hosts one or more VPCs. A virtual network 212, such as, for example, an SDN, that provides logical network abstraction across the physical network 210 may constitute at least a portion of a VPC that includes a plurality of network nodes 204. The network nodes 204, such as, for example, virtual machines, virtual routers, virtual router interfaces, physical hosts mapped via virtual endpoints, physical routers mapped via virtual endpoints, containers, unikernels, one or more virtual resources or hardware resources, or a combination thereof, or the like, or a combination thereof, are hosted (executed) by one or more of a plurality of physical nodes connected to the network 210, such as, for example, servers, switches, routers, network equipment, or the like, or a combination thereof.
[0063] One or more of the hosting physical network nodes comprising one or more processors and memory resources for a program store and / or a data store may execute one or more software modules, such as a process, script, application, agent, utility, tool, operating system (OS), service, plugin, add-on, or the like, or a combination thereof. Each of the software modules comprises a plurality of program instructions that may be executed by a processor of the physical network node from their respective program stores. In particular, one or more of the physical network nodes may execute a virtual network controller 102 to configure, control, or monitor, or a combination thereof, the virtual network 212. For example, in the case of SDN, one or more instances of an SDN controller may be executed by one or more of the physical network nodes to configure, control, or monitor, or a combination thereof, the SDN. Optionally, one or more of the network nodes 204, specifically, the virtualized network nodes 204 may execute one or more instances of an SDN controller.
[0064] The switch 206 that connects the physical server 202 to the network 210 may be regarded as an edge switch since the switch 206 is placed at the edge of the virtual network 212 in relation to the physical server 202. The switch 206 may include one or more hardware elements and may perform, implement, or facilitate, or a combination thereof, the link layer agent 106. The switch 206 may include one or more hardware elements, such as, for example, circuits, components, integrated circuits (ICs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), digital signal processors (DSPs), network processors, or the like, or a combination thereof. Optionally, the switch 206 may include one or more processors and memory resources for a program store or a data store, or both, to execute one or more software modules each comprising a plurality of program instructions that may be executed by a processor of the switch 206 from the program store of the switch 206. Thus, the link layer agent 106 deployed on the switch 206 may be realized, implemented, or executed, or those things may be done, by a software module, a hardware element, or a combination thereof of the switch 206. The link layer agent 106 may be configured to create an LLDP configuration PDU with a virtual network setting and transmit the LLDP configuration PDU via the network 210.
[0065] The enhanced network interface 220 may include sufficient processing resources, memory resources, and networking resources to process data packets exchanged between the physical server 202 and the network nodes 204 of the virtual network 212 by one or more virtualization protocols or virtual network tunneling protocols, or both, that implement the virtual network 212, and that are typically used by the network nodes 204, in order to equip the virtual network port 104. The enhanced network interface 220 may utilize one or more hardware elements, such as circuits, components, ICs, ASICs, FPGAs, DSPs, network processors, or the like, or combinations thereof, to execute process 130. The enhanced network interface 220A may optionally include one or more processors and memory resources for a program store or data store, or both, to execute a plurality of software modules each comprising a plurality of program instructions executable by a processor of the enhanced network interface 220 from a program store of the enhanced network interface 220. Thus, the virtual network port 104 executed by the enhanced network interface 220 may be realized, implemented, or executed, or combinations thereof, by software modules, hardware elements, or combinations thereof. Note that the execution environment of the enhanced network interface 220 is completely separated from the execution environment of the physical server 202 such that there is complete isolation between the two execution environments. Thus, the execution environment of the physical server 202, which may be under the control of a client, is not subject to being compromised, put at risk, or a combination thereof.
[0066] As shown in 112, the virtual network controller 102, e.g., an SDN controller, calculates one or more virtual network settings for the virtual network port 104 deployed to map the physical server 202 in the virtual network 212, such as a VNID, VPC ID, IP address, MAC address, one or more SG (security group) settings, or the like, or a combination thereof, associated with the physical server 202.
[0067] The virtual network controller 102 may calculate the virtual network settings to comply with the settings of the virtual network 212. For example, the VNID assigned to the virtual network port 104 by the virtual network controller 102 is the identifier (ID) of the virtual network 212. In another embodiment, since the virtual network 212 may be part of a VPC, the VPC ID assigned to the virtual network port 104 by the virtual network controller 102 is the identifier (ID) of the VPC. In another embodiment, the IP address assigned to the virtual network port 104 by the virtual network controller 102 is within the range of the IP addresses of the virtual network 212, i.e., within the range of the IP addresses assigned to the network node 204. In another embodiment, the MAC address assigned to the virtual network port 104 by the virtual network controller 102 is a unique MAC in the virtual network 212, i.e., different from the MAC addresses of all network nodes 204.
[0068] As shown at 114, the virtual network controller 102 transmits virtual network settings via network 210 to an enhanced network interface 220 configured to deploy virtual network ports 104. Specifically, the virtual network controller 102 may transmit virtual network settings to a physical server 202 via one or more link layer agents deployed at one or more of the physical network nodes connected to network 210, for example, switch 206.
[0069] The virtual network controller 102 may communicate with one or more of the LLDP agents using one or more network protocols, for example, SNMP, NETCONF, or the like, or a combination thereof, such as network management protocols. Using such network protocols, the virtual network controller 102 may transmit virtual network settings to the LLDP agents.
[0070] As shown at 122, a link layer agent 106 configured to support one or more of the network link layer configuration protocols, for example, the LLDP protocol extended to support the delivery of virtual network settings, may transmit the received virtual network settings in one or more configuration PDUs of the extended LLDP protocol. Specifically, the link layer agent 106 may transmit virtual network settings in one or more configuration PDUs defined by the DCBX protocol, which is an extension of the LLDP protocol. DCBX may be extended to include one or more extended TLVs defined to include virtual network settings and to be transmitted in one or more of the configuration PDUs.
[0071] The enhanced network interface 220 configured to deploy the virtual network port 104 is further configured to receive, decode, process, and apply an extended TLV that encodes the virtual network settings assigned to the virtual network port 104.
[0072] The transmission of the extended configuration message encoding the virtual network settings from the virtual network controller 102 to the switch 206 and further to the enhanced network interface 220 may depend on the implementation details. For example, the virtual network controller 102 may use the control plane or the management plane, or both, of the network 210 to send the virtual network settings to the link layer agent 106 deployed on the switch 206. Then, the link layer agent 106 configured to support the processing or encoding, or both, of the extended TLV may encode the received virtual network settings in one or more TLVs. Using the flow control engine of the link layer 106, the link layer 106 may send one or more configuration PDUs comprising the extended TLV to the enhanced network interface 220.
[0073] As shown in 132, the enhanced network interface 220, particularly the virtual network port 104, receives a configuration PDU that includes an extended TLV that encodes the virtual network settings assigned to the virtual network port 104 to map the physical server 202 in the virtual network 212. The virtual network port 104 may extract the extended TLV from the received configuration PDU and may decode the received extended TLV to extract the encoded virtual network settings.
[0074] The transmission of the extended TLV from the switch 206 and the reception of the extended TLV at the enhanced network interface 220 are performed using the link layer, specifically, the LLDP protocol and the DCBX extension protocol of the LLDP protocol. Therefore, the TLV may be transmitted in one or more configured PDUs of LLDP by applying link layer flow control regarding PDU transmission and positive response signals.
[0075] Accordingly, the link layer agent 106 may allocate and manage one or more memory structures, such as buffers, of the switch 206 to store the extended TLV with the virtual network settings assigned for the virtual network port 104. Using the data processing engine and the flow control engine of the switch 206, the link layer agent 106 may transmit a first configured PDU of the LLDP protocol or the DCBX protocol comprising at least a portion of the first extended TLV retrieved from the buffer. Next, the link layer agent 106 may wait for a positive response signal transmitted by the enhanced network interface 220 in response to the reception of the first configured PDU. After the positive response signal is received and identified by the flow control engine of the switch 206, the link layer agent 106 may transmit a second configured PDU of the LLDP protocol or the DCBX protocol comprising another portion of the first extended TLV retrieved from the buffer, or at least a portion of a second extended TLV. This process may continue until all the extended TLVs stored in the buffer are transmitted to the enhanced network interface 220. Each extended TLV that has been successfully transmitted may be removed from the buffer. However, the extended TLV, or a portion of the extended TLV, or a combination thereof (i.e., each positive response signal is not received at the switch 206) included in the configured PDU that has failed to be properly received by the enhanced network interface 220 may be retransmitted to the enhanced network interface 220 by the link layer agent 106.
[0076] The enhanced network interface 220 that executes the virtual network port 104 may apply a similar mechanism to store the extended TLV received from the switch 206 in one or more memory structures allocated and managed by the enhanced network interface 220, such as a buffer. Using the data processing engine and flow control engine of the enhanced network interface 220, the virtual network port 104 may receive a configuration PDU of the LLDP protocol or DCBX protocol with an extended TLV, and may respond with a respective positive response signal each time a configuration PDU is received.
[0077] As shown in 134, the virtual network port 104 may apply the virtual network settings assigned by the virtual network controller 102 to map the physical server 202 in the virtual network 212 to support data packet transfer between the physical server 202 and the network node 204. For example, the virtual network port 104 may update the virtual network settings in one or more data plane mapping records, such as a routing table, routing map, memory, database, or the like, or a combination thereof, used by the enhanced network interface 220 to resolve the source address or destination address, or both, for transmitted or received packets, or both.
[0078] As shown at 136, after applying the virtual network configuration, the virtual network port 104 may exchange packets between the physical server 202 and one or more of the network nodes 204 on the virtual network 212 by processing the packets with one or more of the virtualization protocols or virtual network tunneling protocols, or both, used in the virtual network 212. This processing may include, for example, encapsulation and decapsulation, packet filtering, implicit packet routing, ARP responses, and others. For example, the virtual network port 104 may encapsulate outgoing packets and decapsulate incoming packets with one or more of the virtual network encapsulation protocols using one or more of the virtual network configurations. To this end, the virtual network port 104 may encapsulate one or more data packets, such as unicast packets, multicast packets, or broadcast packets, or a combination thereof, transmitted from the physical server 202 to one or more of the network nodes 204 in one or more encapsulated packets compliant with the virtual network encapsulation protocols used in the virtual network 212, such as VXLAN, NVGRE, GENEVE, STT, or the like, or a combination thereof. Complementarily, the virtual network port 104 may decapsulate one or more encapsulated packets, such as unicast packets, multicast packets, or broadcast packets, or a combination thereof, received from one or more of the network nodes 204 and transfer the extracted packets to the physical server 202.
[0079] For example, virtual network port 104 may encapsulate packets transmitted by physical server 202 in one or more encapsulated packets having headers compliant with a virtual network encapsulation protocol, such as VXLAN, used in virtual network 212. The header may naturally include the VNID of virtual network 212. The header may further include a source IP address (i.e., the IP address assigned to virtual network port 104) and the IP address of destination network node 204 to which the packet is being sent. If virtual network 212 is at least part of a VPC, virtual network port 104 may include the VPC ID of the VPC in the header of the encapsulated packet. Optionally, virtual network port 104 includes a source MAC address (i.e., the MAC address assigned to virtual network port 104) and the MAC address of the destination network node. In another example, virtual network port 104 may include a security group association of physical server 202 in the header of the virtualized packet in order to comply with security controls applied in virtual network 212, which are typically security controls of the VPC.
[0080] Next, reference is made to FIG. 3, which is an exemplary sequence for providing virtual network settings to a virtual network port that maps a physical server in a virtual network to support packet transfer between a physical server and a node connected to a virtual network, according to some embodiments of the present invention. Exemplary sequence 300 shows the path of virtual network settings transmitted from an (edge) switch such as switch 206 by processes 110, 120, and 130 to configure a virtual network port such as virtual network port 104 that is deployed at an enhanced network interface such as enhanced network interface 220 of a physical server such as physical server 202 to map the physical server 202 in a virtual network such as virtual network 212 that provides an abstraction layer across a network such as network 210 as shown in system 200.
[0081] A virtual network controller such as virtual network controller 102 may calculate (302) one or more of the virtual network settings assigned to virtual network port 104 that maps physical server 202, as described in step 112 of process 110. The virtual network settings may include, for example, the VNID of virtual network 212, the MAC address assigned to virtual network port 104, the IP address of virtual network port 104, and SG settings for associating physical server 202 with a security group in virtual network 212.
[0082] A virtual network controller 102 that uses a control plane of a virtual network 212 by one or more of network management protocols (e.g., SNMP, NETCONF) may send virtual network settings to a link layer agent 106 deployed on a switch 206 as described in step 114 of process 110. In particular, the virtual network controller 102 may create one or more TLVs defined by an extended link layer configuration protocol, e.g., LLDP, in particular, a DCBX extension protocol for the LLDP protocol, as described in step 122 of process 120.
[0083] The link layer agent 106 may store received extended TLVs with virtual network settings in one or more memory structures 304 allocated at the switch 206, e.g., a buffer. Using a data processing engine and a flow control engine of the switch 206, the link layer 106 may send one or more configuration PDUs 306 of LLDP, specifically DCBX, with the extended TLVs stored in the buffer 304 to an enhanced network interface 220.
[0084] The virtual network port 104 may receive configuration PDUs and extract extended TLVs from the configuration PDUs using a data processing engine and a flow control engine of the enhanced network interface 220. The virtual network port 104 may store the extracted extended TLVs in one or more memory structures, e.g., a buffer, allocated and managed on the enhanced network interface 220 side. The virtual network port 104 may further respond to the reception of each configuration PDU with a respective positive response signal 310 using a flow control engine of the enhanced network interface 220.
[0085] When the reception of the extended TLV 312 including the virtual network settings assigned to the virtual network port 104 is completed, the virtual network port 104 may extract the virtual network settings 314 from the extended TLV and apply the virtual network settings 314 to one or more data plane control modules used by the enhanced network interface 220 to resolve the source address or destination address, or both, of the transmitted packet or received packet, or both. For example, the virtual network port 104 may update the virtual network settings (316) in one or more of the data plane mapping records in the enhanced network interface 220, such as a routing table, a routing map, a memory, a database, or the like, or a combination thereof.
[0086] After the virtual network port 104 is properly deployed and configured in the network interface 220 enhanced by the received virtual network settings, the virtual network port 104 may start processing (320) data packets transferred between the physical server 202 and one or more of the network nodes 204 of the virtual network 212 as described in step 136 of process 130. For example, in the egress path, the virtual network port 104 may encapsulate one or more data packets (e.g., unicast packets, multicast packets, or broadcast packets, or a combination thereof) transmitted from the physical server 202. The virtual network port 104 may encapsulate the outgoing packets into one or more encapsulated packets by using a virtual network encapsulation protocol used in the virtual network 212, such as VXLAN, with the virtual network settings assigned to the virtual network port 104. Finally, the virtual network port 104 may transmit the encapsulated packets via the virtual network 212. In the ingress path, the virtual network port 104 may receive one or more incoming packets (e.g., unicast packets, multicast packets, or broadcast packets, or a combination thereof) from one or more of the network nodes 204 via the virtual network 212. The virtual network port 104 may use the virtual network settings to decapsulate incoming packets that may be encapsulated, e.g., by a virtual network encapsulation protocol used in the virtual network 212, such as VXLAN, in order to process the incoming packets. Next, the virtual network port 104 may transfer the data packets extracted from the encapsulated packets to one or more software modules executed by the physical server 202.
[0087] Next, reference is made to FIGS. 4A and 4B, which present a schematic diagram of an exemplary state machine developed to queue, transmit, and receive virtual network settings provided to a virtual network port that maps a physical server in a virtual network to support packet transfer between the physical server and a node connected to the virtual network, according to some embodiments of the present invention. Note that some of the embodiments presented in FIGS. 4A and 4B are directed to the VXLAN virtual network encapsulation protocol. However, the implementation of the VXLAN encapsulation protocol is exemplary and should not be construed as limiting, and may equally apply to any other of the encapsulation protocols of virtual network virtualization protocols or virtual network tunneling protocols, or both, such as, for example, NVGRE, GENEVE, STT, or the like, or combinations thereof.
[0088] An exemplary queuing state machine 402 may be applied by a link layer agent 106, such as a switch 206, to queue one or more of the TLVs received from a virtual network controller 102, such as a virtual network controller for a virtual network 212, which provides an abstraction layer across a network such as network 210. The TLVs of the LLDP / DCBX protocol, particularly the extended TLVs added to the LLDP / DCBX protocol to support the transfer of virtual network settings, may include one or more virtual network settings assigned to a virtual network port 104, such as a virtual network port deployed at an enhanced network interface 220, such as an enhanced network interface of a physical server 202, to map the physical server 202 in the virtual network 212. For example, assuming that the virtual network 212 uses the VXLAN encapsulation protocol, the extended TLV may include VXLAN settings assigned to the virtual network port 104 for encapsulation and decapsulation of data packets exchanged between the physical server 202 and one or more network nodes, such as network node 204 of the virtual network 212. As can be seen, the queuing state machine 402 supports the reception of multiple extended TLVs and may push each received TLV into the queue.
[0089] The exemplary transmission state machine 404 may be applied by the link layer agent 106 deployed on the switch 206 to control the transmission of configuration PDUs including extended TLVs by an extended LLDP protocol, specifically, an extended DCBX protocol. The transmission state machine 404 may process the extended TLVs and create one or more configuration PDUs, such as LLDP / DCBX PDUs, to include extended TLVs including virtual network settings. Continuing with the foregoing example, assuming that the virtual network 212 uses the VXLAN encapsulation protocol, the transmission state machine 404 may create and construct one or more LLDP / DCBX PDUs with TLVs including VXLAN settings. Next, the transmission state machine 404 may transmit each of the LLDP / DCBX PDUs and wait for an affirmative response signal indicating the reception of each LLDP / DCBX PDU by the enhanced network interface 220. The transmission state machine 404 may retransmit one or more LLDP / DCBX PDUs for which the affirmative response signal is not received. The number of retries may be predefined.
[0090] The exemplary receive state machine 406 may be applied by the virtual network port 104 deployed on the enhanced network interface 220 to control the reception of a configured PDU that includes extended TLVs, such as an LLDP / DCBX PDU. The receive state machine 406 may receive an LLDP / DCBX PDU from the link layer agent 106 deployed at the switch 206 and, optionally, verify the received PDU to ensure the integrity of the received PDU. Continuing with the foregoing example, assuming that the virtual network 212 uses the VXLAN encapsulation protocol, the LLDP / DCBX PDU received and verified by the receive state machine 406 may include one or more of the extended TLVs that include VXLAN settings. Next, the receive state machine 406 may send an acknowledgment signal for each received LLDP / DCBX PDU. The receive state machine 406 may further resend the acknowledgment signal for each retransmitted LLDP / DCBX PDU. The receive state machine 406 may extract the extended TLV from the LLDP / DCBX PDU and store the extracted extended TLV in a queue that may be used to transfer the extended TLV, particularly the VXLAN settings for one or more upper level protocols (ULPs) included in the extended TLV, such as virtual network settings.
[0091] Such a ULP may apply, use, or both, the virtual network settings received to map the physical server 202 in the virtual network 212, and may be utilized by the virtual network port 104 to enable packet transfer between the physical server 202 and the network node 204. For example, assuming that the virtual network 212 uses the VXLAN encapsulation protocol and the received virtual network settings are VXLAN settings, the virtual network port 104 may apply, use, or both, the received VXLAN settings to encapsulate outgoing packets from the physical server 202 or to decapsulate incoming packets to the physical server 202. In another embodiment, the virtual network settings may include one or more security group parameters required to enforce one or more security policies in the virtual network 212. The virtual network port 104 may apply, use, or both, the received security group parameters to comply with and follow the security policies applied in the virtual network 212. In another embodiment, the virtual network settings may include one or more multicast grouping parameters to form one or more multicast groups of the computing nodes 204 in the virtual network 212. The virtual network port 104 may apply, use, or both, the received multicast grouping parameters to participate in one or more of these multicast groups or to support data exchange with one or more of these multicast groups. In another embodiment, the virtual network settings may include one or more additional parameters required to correct the functionality of the virtual network 212.A virtual network port 104 that executes one or more network correction algorithms may apply, use, or both apply and use additional parameters received to support network function correction.
[0092] During the term of the patents maturing from this application, many related systems, methods, and computer programs are expected to be developed, and the terms virtualization protocol, tunneling protocol, encapsulation protocol, and link layer configuration protocol are intended to include a priori all such new technologies.
[0093] As used herein, the term "about" refers to ±10%.
[0094] "Comprising," "comprised of," "including," "included," "having," and their conjugations mean "including but not limited to."
[0095] The term "consisting of" means "including and limited to."
[0096] As used herein, the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. For example, the term "a composition" or "at least one composition" may include plural compositions, including mixtures thereof.
[0097] Throughout this application, various embodiments of the invention may be presented in a range format. It should be understood that the description in range format is for convenience and brevity only and should not be construed as an inflexible limitation on the scope of the invention. Accordingly, a description of a range should be considered to specifically disclose all the sub-ranges within the possible range, as well as the individual numerical values within that range. For example, a description of a range such as from 1 to 6 should be considered to specifically disclose sub-ranges such as from 1 to 3, from 1 to 4, from 1 to 5, from 2 to 4, from 2 to 6, from 3 to 6, and others, and also the individual numbers within that range, such as 1, 2, 3, 4, 5, and 6. This applies regardless of the width of the range.
[0098] Whenever a numerical range is indicated herein, it is intended to include any number (fractional or integral) recited within the indicated range. The phrases "range between" a first indicated number and a second indicated number, and "range from" a first indicated number "to" a second indicated number are used interchangeably herein and are intended to include the first and second indicated numbers, and all fractional and integral numbers therebetween.
[0099] It will be recognized that some features of the invention described in the context of separate embodiments may be provided in combination in a single embodiment. Conversely, for simplicity, various features of the invention described in the context of a single embodiment may be provided separately, or in any suitable partial combination, in any other described embodiment of the invention as appropriate. Some features described in the context of various embodiments should not be considered essential features of those embodiments unless the embodiments would not operate without those elements.
[0100] Although the embodiments described in this specification have been described in connection with specific embodiments thereof, it will be apparent to those skilled in the art that many alternative, modification, and variation forms are obvious. Therefore, it is intended that all such alternative, modification, and variation forms included within the spirit and broad scope of the appended claims be encompassed.
[0101] All publications, patents, and patent applications mentioned in this specification are hereby incorporated by reference in their entirety to the same extent as if each individual publication, patent, and patent application were specifically and individually indicated to be incorporated by reference. Furthermore, any reference or identification of a reference in this application should not be construed as an admission that such reference is available as prior art for the embodiments described in this specification. To the extent that section headings are used, they should not necessarily be construed as limiting. Additionally, any priority documents of this application are hereby incorporated by reference in their entirety.
Claims
1. A method for configuring a virtual port for a physical server to support packet transfer between the physical server and other network nodes on a virtual network, comprising: Transmitting at least one configuration protocol data unit (PDU) of an extended link layer data protocol (LLDP) to a network interface card (NIC) of a physical server connected to the network, wherein the at least one configuration PDU comprises at least one extended Type Length Value (TLV) defining at least one virtual network setting for a virtual network port that maps the physical server in the virtual network, using at least one processor provided in one or more of the physical network nodes connected to the network for said transmitting; The NIC comprises independent processing resources and memory resources that are completely separated from the execution environment of the physical server, and the NIC is configured to execute the virtual network port by using the independent processing resources and memory resources to process outgoing and incoming packets by at least one virtual network virtualization protocol using the at least one virtual network setting, so as to support packet exchange between the physical server and at least one of the plurality of nodes of the virtual network.
2. The method according to claim 1, wherein the virtual network is at least part of a virtual private cloud (VPC).
3. The method according to claim 1, wherein the physical server is a bare metal server deployed as part of a VPC.
4. The method according to claim 1, wherein the at least one virtual network virtualization protocol comprises at least one virtual network encapsulation protocol, and the virtual network port supports packet exchange by encapsulating and decapsulating outgoing and incoming packets by the at least one virtual network encapsulation protocol using the at least one virtual network setting.
5. The method according to claim 4, wherein the at least one virtual network encapsulation protocol is a member of a group consisting of Virtual Extensible Local Area Network (VXLAN), Network Virtualization using Generic Routing Encapsulation (NVGRE), Generic Network Virtualization Encapsulation (GENEVE), and Stateless Transport Tunneling (STT).
6. The method according to claim 1, wherein the at least one configuration PDU is defined by an extended Data Center Bridging Exchange (DCBX) extension of the LLDP, and the extended DCBX is extended to support the at least one extended TLV.
7. The method according to claim 1, wherein the at least one virtual network setting is a member of a group consisting of a virtual network address assigned to the virtual network port deployed in the NIC to map the physical server within a range of virtual addresses of the virtual network, a virtual network identifier (VNID) of the virtual network, a VPC identifier (VPC ID), a security group association related to the physical server, and a multicast group association related to the physical server.
8. The method according to claim 7, wherein the virtual network address defines an Internet Protocol (IP) address assigned to the virtual network port deployed in the NIC within the range of the IP addresses of the virtual network.
9. The method according to claim 8, further comprising defining a Media Access Control (MAC) address assigned to the virtual network port by the virtual network address, and the virtual network port applying the IP address and the MAC address for encapsulation and decapsulation.
10. The method according to claim 1, wherein each of the packets exchanged between the NIC of the physical server and at least one node of the virtual network is a member of a group consisting of a unicast packet, a multicast packet, and a broadcast packet.
11. A system for configuring a virtual port for a physical server to support packet transfer between the physical server and other network nodes on a virtual network, at least one processor executing code comprising code instructions for transmitting at least one configuration protocol data unit (PDU) of an Extended Link Layer Discovery Protocol (LLDP) to a network interface card (NIC) of a physical server connected to a network, the at least one configuration PDU comprising at least one extended Type Length Value (TLV) defining at least one virtual network setting for a virtual network port mapping the physical server in a virtual network. The NIC includes independent processing resources and memory resources that are completely separated from the execution environment of the physical server, and the NIC processes outgoing packets and incoming packets by using at least one virtual network virtualization protocol with at least one virtual network setting, so as to support packet exchange between the physical server and at least one of a plurality of nodes of the virtual network. A system configured to execute the virtual network port using the independent processing resources and memory resources.
12. The system according to claim 11, wherein the virtual network is at least a part of a virtual private cloud (VPC).
13. The system according to claim 11, wherein the physical server is a bare metal server deployed as a part of a VPC.
14. The system according to claim 11, wherein each of the packets exchanged between the NIC of the physical server and at least one node of the virtual network is a member of a group consisting of unicast packets, multicast packets, and broadcast packets.
15. A computer program product for configuring a virtual port for a physical server to support packet transfer between the physical server and other network nodes on a virtual network, A non-transitory computer-readable storage medium, and A first program instruction for transmitting at least one configuration protocol data unit (PDU) of an extended Link Layer Discovery Protocol (LLDP) to a network interface card (NIC) of a physical server connected to a network, wherein the at least one configuration PDU comprises at least one extended Type Length Value (TLV) defining at least one virtual network setting for a virtual network port mapping the physical server in a virtual network, the NIC comprises independent processing resources and memory resources completely separated from the execution environment of the physical server, and the NIC is configured to execute the virtual network port by using the at least one virtual network setting to process outgoing and incoming packets by at least one virtual network virtualization protocol, so as to support packet exchange between the physical server and at least one of a plurality of nodes of the virtual network, and by using the independent processing resources and memory resources. The first program instruction is provided. A computer program product, wherein the first program instruction is executed by at least one processor from the non-transitory computer-readable storage medium. **Claim 16** The computer program product according to claim 15, wherein the at least one virtual network virtualization protocol comprises at least one virtual network encapsulation protocol, and the virtual network port supports packet exchange by encapsulating and decapsulating outgoing and incoming packets by using the at least one virtual network setting and the at least one virtual network encapsulation protocol. **Claim 17** The computer program product according to claim 16, wherein the at least one virtual network encapsulation protocol is a member of the group consisting of Virtual Extensible Local Area Network (VXLAN), Network Virtualization using Generic Routing Encapsulation (NVGRE), Generic Network Virtualization Encapsulation (GENEVE), and Stateless Transport Tunneling (STT).
18. The computer program product according to claim 15, wherein the at least one configured PDU is defined by an extended Data Center Bridging Exchange (DCBX) extension of the LLDP, and the extended DCBX is extended to support the at least one extended TLV.
19. The computer program product according to claim 15, wherein the at least one virtual network configuration is a member of the group consisting of a virtual network address assigned to a virtual network port deployed in the NIC to map the physical server within a range of virtual addresses of the virtual network, a virtual network identifier (VNIID) of the virtual network, a VPC identifier (VPC ID), a security group association related to the physical server, and a multicast group association related to the physical server.
20. The computer program product according to claim 15, wherein each of the packets exchanged between the NIC of the physical server and the at least one node of the virtual network is a member of the group consisting of a unicast packet, a multicast packet, and a broadcast packet.
Citation Information
Patent Citations
Method and apparatus of cloud computing subsystem
JP2014023142A
Auto-discovery of replication node and remote VTEPs in VXLANs
US10103902B1
System and Method to Create Virtual Links for End-to-End Virtualization
US20120042095A1
Overlay tunnel information exchange protocol
US20130311637A1
Establishing an ipsec (internet protocol security) VPN (virtual private network) tunnel
US20140068750A1