Direct Host Return Ports Bypass Gateways for Egress Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face inefficiencies in handling tenant networks that transmit substantial amounts of data outside the managed network, particularly in datacenters with sophisticated setups involving virtual machine migration, dynamic workloads, and multi-tenancy, where existing solutions do not adequately optimize packet forwarding.
Innovation Solution
Implementing a managed network with direct host return (DHR) ports that allow managed forwarding elements to send packets directly to the external network, bypassing gateways, through the use of logical forwarding elements and a network controller cluster configuring edge managed forwarding elements to process packets using flow entries stored in forwarding tables.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packets are sent through gateway machines for external network communication, then network management and security control are improved, but packet forwarding efficiency and network performance deteriorate due to additional processing hops
Solution Approach 1:
The patent segments the network communication path by introducing Direct Host Return (DHR) ports that create a separate direct connection channel from virtual machines to external networks, bypassing the gateway machines. This segmentation allows packets to be routed through different paths: management traffic through gateways and data traffic through direct DHR connections, thereby resolving the contradiction between control reliability and forwarding efficiency.
2Reliability
If gateway machines handle all external network traffic, then centralized security management is improved, but processing load on gateways increases and overall network performance deteriorates
Solution Approach 1:
The patent extracts the data forwarding function from the gateway machines by implementing DHR ports on host machines. This extraction removes the burden of handling large volumes of data traffic from gateways, allowing them to focus on security management and control functions, while the host machines directly handle data transmission to external networks, thereby reducing processing load and energy consumption on gateways.
3Device complexity
If traditional network paths are used for egress traffic, then network topology simplicity is maintained, but packet forwarding efficiency deteriorates due to unnecessary hops through gateway machines
Solution Approach 1:
The patent introduces DHR ports as intermediary elements that facilitate direct communication between virtual machines and external networks. These DHR ports act as mediators that enable short-circuiting of the traditional packet path, allowing egress traffic to bypass gateway machines and reach external networks directly, thereby improving forwarding efficiency without significantly complicating the overall network topology.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system that allows for the use of direct host return ports (abbreviated "DHR ports") on managed forwarding elements 215, 225 to bypass gateways 250 in managed networks 200. The DHR ports provide a direct connection from certain managed forwarding elements 215, 225 in the managed network 200 to remote destinations 230 that are external to the managed network. Managed networks 200 can include both a logical abstraction layer and physical machine layer. At the logical abstraction layer, the DHR port is treated as a port on certain logical forwarding elements. The DHR port transmits the packet to the routing tables of the physical layer machine 210, 220 that hosts the logical forwarding element without any intervening transmission to other logical forwarding elements. The routing tables of the physical layer machine 210, 220 then strip any logical context associated with a packet and forwarding the packet to the remote destination 230 without any intervening forwarding to a physical gateway provider 250.