Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Virtual routing and forwarding" patented technology

In IP-based computer networks, virtual routing and forwarding (VRF) is a technology that allows multiple instances of a routing table to co-exist within the same router at the same time. One or more logical or physical interfaces may have a VRF and these VRFs do not share routes therefore the packets are only forwarded between interfaces on the same VRF. VRFs are the TCP/IP layer 3 equivalent of a VLAN. Because the routing instances are independent, the same or overlapping IP addresses can be used without conflicting with each other. Network functionality is improved because network paths can be segmented without requiring multiple routers .

Network intercommunication method and system, electronic equipment, storage medium and program product

The invention discloses a network intercommunication method and system, electronic equipment, a storage medium and a program product, and relates to the field of cloud computing, and the method comprises the following steps: for first virtual machine traffic output by a virtual machine in a computing node, performing route matching on the first virtual machine flow through a routing table corresponding to a first virtual route and a forwarding instance in the computing node; and instructing a target switch to send the obtained second virtual machine traffic to the physical server node, so that network intercommunication between the virtual machine and the physical server node is realized, and the target switch is connected to the physical server node, the routing reflector and the computing node. The problem that the network intercommunication effect between the virtual machine and the bare metal node is poor due to the defects of bandwidth forwarding bottleneck and high scheme cost of a soft gateway used between the virtual machine and the bare metal node in the computing node in the cloud computing environment is solved, and the network intercommunication effect between the virtual machine and the bare metal node is improved.
Owner:JINAN INSPUR DATA TECH CO LTD

Methods for Onboarding Network Devices in Disaggregated Scheduled Fabrics and Systems Thereof

Devices, networks, systems, methods, and processes for onboarding a network device in a cluster in a Disaggregated Scheduled Fabric (DSF) are described herein. To associate with the cluster, the network device can determine a cluster size. The network device may determine a switch identifier based on the cluster size. The network device can reserve a set of system ports for in-band communication. The network device may assign at least one in-band communication interface to the set of system ports. The network device may instantiate a Virtual Routing and Forwarding (VRF) instance for the at least one in-band communication interface. The network device can generate a custom Media Access Control (MAC) address and a custom Internet Protocol (IP) address based on the switch identifier. The network device may establish one or more in-band communication sessions with other network devices in the cluster based on the at least one in-band communication interface.
Owner:CISCO TECHNOLOGY INC

Route distinguishers for same destination path diversity

PendingUS20260205411A1PathPingPrivate network
This disclosure describes techniques for using multiple route distinguishers assigned to a single VRF to provide same-destination path diversity in a VPN. In an example, a method includes storing, by a device, to a single virtual routing and forwarding instance (VRF) of one or more VRFs configured for a network device of a network, a plurality of routes for a common address prefix of a virtual private network (VPN); and sending, by the device to a network router, each of the plurality of routes for the common address prefix with a different, corresponding route distinguisher.
Owner:JUNIPER NETWORKS INC

AUTOMATED CLIENT PROVISION

The systems and methods disclosed herein are designed for a network to use virtual routing and forwarding (VRF) for tenant provisioning. The network may include a network device and an authentication server or service. The network device may submit an authentication request and a VRF request to the authentication server or service. The authentication server or service may return a VRF reference to the network device. The network device may also, on behalf of a tenant and as part of resource provisioning for the tenant, include the tenant in a VRF associated with the VRF reference.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Mapping of ipsec tunnels to sd-wan segmentation

Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.
Owner:CISCO TECHNOLOGY INC

Isolating time synchronization traffic using virtualization

This disclosure describes techniques for customer isolation using virtualization to provide time synchronization services. For example, one method includes: receiving, by a computing device, Internet Protocol (IP) addresses of customer networks among multiple customer networks connected to a cloud exchange performed by the computing device; configuring, by the computing device, a time synchronization server connected to the cloud exchange using a virtualized local area network (VLAN) associated with the IP addresses of the customer networks, the time synchronization server including multiple instances providing time synchronization services; and configuring, by the computing device, the time synchronization server using Virtual Routing and Forwarding (VRF) or network namespaces for VLANs, wherein the VRF or network namespace includes routes for sending time synchronization services between the customer networks and specific instances among the multiple instances providing time synchronization services.
Owner:EQUINIX INC

Direct link cross-VRF communication method, device, equipment and medium

The invention relates to a link cross-VRF communication method and device, equipment and a medium, and relates to the technical field of communication. The method comprises the following steps: when a first message of a first virtual private network (VPN) is received, extracting a destination IP address in the first message; wherein the first message comes from a first host under a first virtual routing and forwarding VRF identifier, and the destination IP address does not belong to a host address under the first VRF identifier in the first VPN; determining a second VRF identifier corresponding to the destination IP address based on the destination IP address and a mapping relation table; and determining a forwarding path of the first message based on the destination IP address and the second VRF identifier. By adopting the method, the access of a large number of direct connection equipment can be realized.
Owner:SHEN ZHOU SHU MA WANG LUO BEI JING YOU XIAN GONG SI

Overlay from on-premises router to cloud service provider environment for telecommunication network functions (NFs) to handle multiple virtual routing and forwarding (VRF) protocols

Embodiments are directed towards systems and methods for routing network traffic in a fifth-generation New Radio (5G NR) cellular telecommunication network radio access network (RAN) to network functions provided in a cloud service provider environment. One such method includes: configuring first virtual routing and forwarding (VRF) instances on a first router device using information that identifies the network functions and information that identifies Internet Protocol (IP) subnets; configuring second VRF instances on a second router device using information that identifies the network functions and information that identifies the subnets; controlling a first virtual private cloud (VPC) in the cloud service provider environment, the first VPC performing a first network function; and transmitting a first network packet to the first VPC using a first one of the first VRF instances and a first one of the second VRF instances.
Owner:BOOST SUBSCRIBERCO LLC

Mapping of IPSec tunnels to SD-WAN segmentation

Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.
Owner:CISCO TECHNOLOGY INC

Secure packet transmission method and related apparatus

This disclosure provides a secure packet transmission method, a method for negotiating an internet protocol security security association (IPsec SA), and a related apparatus, and is applied to a wide area network. In a scenario of crossing a plurality of segments of tunnels, an IPsec SA used for end-to-end security protection is negotiated between a first site edge and a second site edge based on a virtual routing and forwarding (VRF) granularity by extending a border gateway protocol (BGP) route. After performing security protection on a virtual private network (VPN) service packet based on the IPsec SA, the first site edge sends the packet through an overlay end-to-end tunnel between the first site edge and the second site edge, and the second site edge processes the packet based on the IPsec SA, to obtain the VPN service packet.
Owner:HUAWEI TECH CO LTD

Using UDP port numbers for service delimiting, such as for delimiting virtual routing and forwarding instances in layer 3 tunnels

ActiveUS12568047B2Data switching networksWireless communicationMultiprotocol Label SwitchingData center
Different services through Virtual Routing and Forwarding instances (VRFs) are identified without needing a Multiprotocol Label Switching (MPLS) label or a Virtual Extensible Local Area Network (VXLAN) Network Identifier (VNI) by using, for example, different UDP port numbers to identify different connectivity services (e.g., customers, VRFs) when IP-in-IP (also referred to as IP over UDP) is used as a tunneling mechanism (e.g., in the data center).
Owner:JUNIPER NETWORKS INC

Containerized routing protocol process for VPNs

A containerized routing protocol process for a virtual private network. Generally, this disclosure describes techniques for implementing a virtual private network using a routing protocol using a containerized routing protocol process. In an example, a system includes a container orchestration system for a computing device cluster, the computing device cluster including computing devices, wherein the container orchestration system is configured to: deploy a containerized application to a computing node; and in response to deploying the containerized application to the computing node, configure a virtual routing and forwarding (VRF) instance in the computing node to implement a virtual private network (VPN) for the containerized application.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Traffic control method and related device

Embodiments disclose methods and devices for traffic control. A border gateway protocol (BGP) route advertisement message is sent by a control management device, where the message advertises a virtual private network (VPN) route instructing a device to redirect a VPN route to iterate to a first next hop (a private IP address) of a private network (towards reaching an IP address prefix), the IP address prefix to a destination host, and a network address of the first next hop towards reaching the IP address prefix. A virtual routing and forwarding (VRF) entry, including the IP address prefix and outbound interface information connected to the first next hop, is generated based on the indication information. The outbound interface information is determined in a local VRF table based on the indication information and network address of the first next hop, and the VRF entry is generated and used for controlling network traffic.
Owner:HUAWEI TECH CO LTD

Network intercommunication method, system, electronic device, storage medium and program product

The present application discloses a network intercommunication method, system, electronic device, storage medium and program product, which relate to the field of cloud computing, including: for first virtual machine traffic output by a virtual machine in a computing node and whose destination node is a physical server node, routing matching is performed on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance in the computing node; instructing the target switch to send the obtained second virtual machine traffic to the physical server node, so that the virtual machine and the physical server node can achieve network intercommunication, and the target switch is respectively connected to the physical server node, the route reflector and the computing node. The method solves the problem that the soft gateway used between the virtual machine in the computing node and the bare metal node in the cloud computing environment has a bandwidth forwarding bottleneck and a high solution cost, which leads to poor network intercommunication between the virtual machine and the bare metal node, and improves the network intercommunication between the virtual machine and the bare metal node.
Owner:JINAN INSPUR DATA TECH CO LTD

Prefix summarization scale by deduplicating longest prefix match (LPM) sub-tries

ActiveUS12418483B1TransmissionTheoretical computer scienceLongest prefix match
Techniques for improving the prefix summarization scale of the longest prefix match (LPM) tables of a network device are provided. In one set of embodiments, these techniques involve deduplicating sub-tries of LPM trie data structures that the network device uses to program LPM entries into the LPM tables. This sub-trie deduplication avoids the creation of duplicate LPM entries in the LPM tables across different virtual routing and forwarding (VRF) instances, thereby increasing the LPM tables' effective capacity.
Owner:ARISTA NETWORKS INC

System and method for network traffic processing based on federated services and user groups

The present application relates to a system and method for network traffic processing based on joint services and user groups, and discloses a system comprising: a first modem configured to generate a first data packet (including a first virtual routing and forwarding (VRF) instance identifier associated with a first service, a first user group, or both) based on a first radio frequency (RF) signal; and a second modem configured to generate a second data packet (including a second VRF instance identifier associated with a second service, a second user group, or both) based on a second RF signal. The system comprises a network device configured to receive the first data packet, transmit the first packet (including a first header including a first indicator associated with the first VRF instance) to the first device via a network, receive the second data packet, and transmit the second packet (including a second header including a second indicator associated with the second VRF instance) to the second device via the network.
Owner:THE BOEING CO

System and method for supporting VRF-based traffic isolation across a network with dynamic provisioning

PendingUS20260095407A1TransmissionEngineeringVirtual routing and forwarding
A method for virtual routing and forwarding (VRF) support across a network with dynamic provisioning. A network device receives route information that includes a traffic isolation context label for a traffic isolation context, and host reachability information, where the route information is received over a network interface of the second network device. The network device identifies a target VRF into which to import a route. The network device configures a subinterface on the network interface over which it received the route information, including binding the subinterface to the target VRF and configuring the subinterface to insert the traffic isolation context label into network traffic. The network device imports reachability for a next hop network device and a route into the target VRF.
Owner:ARISTA NETWORKS INC

Prefix Summarization Scale By Deduplicating Longest Prefix Match (LPM) Sub-Tries

ActiveUS20250293977A1TransmissionTheoretical computer scienceLongest prefix match
Techniques for improving the prefix summarization scale of the longest prefix match (LPM) tables of a network device are provided. In one set of embodiments, these techniques involve deduplicating sub-tries of LPM trie data structures that the network device uses to program LPM entries into the LPM tables. This sub-trie deduplication avoids the creation of duplicate LPM entries in the LPM tables across different virtual routing and forwarding (VRF) instances, thereby increasing the LPM tables' effective capacity.
Owner:ARISTA NETWORKS INC

Route advertisement method, apparatus, and system

ActiveUS12621239B2Networks interconnectionIp addressVirtual routing and forwarding
A route advertisement method includes advertising, by a first network device, an Internet Protocol (IP) prefix route to a second network device, where the IP Prefix route includes a gateway (GW) IP address and a Multi-Protocol Label Switching (MPLS) label. The GW IP address is an IP address of a first interface of the first network device. The MPLS Label is a label of a first IP-virtual routing and forwarding (IP-VRF) instance of the first network device. The first network device advertises a media access control (MAC) / IP route to the second network device, where the MAC / IP route includes the IP address of the first interface and a MAC address of the first interface.
Owner:HUAWEI TECH CO LTD

Containerized routing protocol process for virtual private networks

In general, this disclosure describes techniques for leveraging a containerized routing protocol process to implement virtual private networks using routing protocols. In an example, a system comprises a container orchestration system for a cluster of computing devices, the cluster of computing devices including a computing device, wherein the container orchestration system is configured to: deploy a containerized application to a compute node; and in response to deploying the containerized application to the compute node, configure in the compute node a virtual routing and forwarding (VRF) instance to implement a virtual private network (VPN) for the containerized application.
Owner:JUNIPER NETWORKS INC

Packet forwarding method, electronic device, storage medium, and program product

PCT designated stageWO2025246484A1TransmissionService flowPrivate network
Disclosed in embodiments of the present application are a packet forwarding method, an electronic device, a storage medium, and a program product. The packet forwarding method comprises: receiving a virtual routing and forwarding packet sent by a private network device, wherein the virtual routing and forwarding packet carries first target address information; on the basis of the first target address information, determining a first service flow corresponding to the virtual routing and forwarding packet; on the basis of the first service flow and a preset association relationship, determining a first network tunnel corresponding to the virtual routing and forwarding packet, wherein the preset association relationship is a correspondence between identification information of a service flow and a network tunnel, and the identification information of the service flow comprises first identification information of the first service flow; and forwarding, by means of the first network tunnel, the virtual routing and forwarding packet to a target network device corresponding to the first target address information.
Owner:ZTE CORP