Virtual Switch Multicast IP Mapping for Tenant Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems face challenges in managing large numbers of virtual machines and virtual local area networks, particularly in supporting a large number of MAC addresses and transporting traffic over routed infrastructure, which complicates multicast routing in virtualized network environments.
Innovation Solution
The implementation of a method for providing multicast addressing in an overlay network using a first hypervisor managing a virtual switch that maps customer-specific multicast IP addresses to global multicast IP addresses, allowing for efficient packet transmission and reception across multiple virtual machines and tenants, with virtual switches encapsulating packets with global multicast IP addresses for transmission over the physical network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLANs are used to separate tenants in virtualized networks, then network segmentation and tenant isolation are improved, but managing large VLANs becomes difficult and the network cannot efficiently support a large number of MAC addresses
Solution Approach 1:
The patent segments the network addressing space by introducing a hierarchical structure with customer-specific multicast IP addresses (local scope) and global multicast IP addresses (network-wide scope). This segmentation allows multiple tenants to have isolated multicast address spaces while enabling efficient routing across the network without requiring large VLANs.
Solution Approach 2:
The patent adds an addressing dimension by mapping customer-specific addresses to global addresses through a translation mechanism. This dimensional transformation enables multicast traffic to be routed efficiently across the network while maintaining tenant isolation, solving the scalability problem without increasing VLAN management complexity.
2Adaptability or versatility
If a large number of virtual machines are deployed to support many tenants, then network capacity and service coverage are improved, but the number of MAC addresses increases making traffic transport and multicast routing difficult
Solution Approach 1:
The patent introduces global multicast IP addresses as intermediaries between customer-specific multicast addresses and the underlying network infrastructure. This intermediary layer simplifies multicast routing by providing a unified addressing scheme that works across multiple tenants and virtual machines without requiring complex per-VM routing configurations.
Solution Approach 2:
The global multicast IP address space serves multiple functions simultaneously: it provides unique identification for multicast groups across the entire network, enables efficient routing through standard IP multicast mechanisms, and maintains tenant isolation through the mapping relationship with customer-specific addresses. This universal addressing scheme supports arbitrary numbers of VMs without increasing routing complexity.
3Reliability
If customer-specific multicast IP addresses are used for each tenant, then tenant isolation and security are improved, but routing efficiency decreases due to address translation requirements
Solution Approach 1:
The patent performs address mapping in advance by establishing the relationship between customer-specific multicast IP addresses and global multicast IP addresses before multicast traffic flows. This preliminary configuration allows the network to route multicast traffic efficiently using global addresses while maintaining tenant isolation, eliminating the need for real-time address translation during packet forwarding.
Data Source
AI summary
An information handling system is provided. The information handling system includes a first hypervisor running on a first host and a second hypervisor running on a second host. The first hypervisor managing a first virtual switch, and the second hypervisor managing a second virtual switch. The information handling system also includes a plurality of virtual machines (VMs), including a first VM, which is part of a first tenant, running on the first host, and a second VM, part of a second tenant, running on the second host. The first virtual switch has a mapping in memory that maps a customer-specific multicast IP address, used by the plurality of VMs to indicate a multicast group that includes VMs on the first and second tenants, to a global multicast IP address used by the first and second hosts.


