SERVICE INSERTION IN BASIC VIRTUAL NETWORK ENVIRONMENT
A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch. A processing system includes: a service module; a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with virtual machines; a second communication interface for communication with the virtual switch; the first communication interface being associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and wherein the second communication interface is associated with original network segments at the virtual switch.
Latest HILLSTONE NETWORKS CORP. Patents:
This application is a divisional of U.S. patent application Ser. No. 14/691,470 filed on Apr. 20, 2015, issued as U.S. Pat. No. 10,419,365 on Sep. 17, 2019. The entire disclosure of the above application is expressly incorporated by reference herein.
FIELDThis application relates generally to service insertion in virtualized computing environment, like enterprise virtualized server farms, private data center, public cloud, or hybrid cloud, etc.
BACKGROUNDIn Network Function Virtualization (NFV), network services are virtualized. In some cases, it may be possible to deploy network services next to Virtual Machines (VMs), and provide services on the communication between any two VMs in data center, or between any VM and the Internet. In virtualized computing environment, certain Software-defined Networking (SND) technology may be employed to implement service insertion.
Small scale date centers usually do not require a SDN solution to manage its network. However, implementation of virtualized services may still require a SDN solution.
SUMMARYOne or more embodiments described herein provide a technique to insert virtualized services into a basic virtualized computing environment without any SDN support.
A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between a plurality of virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch.
Optionally, the first communication interface is configured for communication with the virtual switch.
Optionally, the first service switch comprises a third communication interface configured for communication with the plurality of virtual machines. The third communication interface may include sub-interfaces for communication with the respective virtual machines.
Optionally, the first service switch is configured to provide VM-based network segments.
Optionally, the VM-based network segments correspond with the plurality of virtual machines, respectively.
Optionally, the virtual switch is also configured to provide original network segments, and wherein the first service machine comprises a mapping for mapping the original network segments and the VM-based network segments.
Optionally, at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
Optionally, one of the virtual machines is configured to communicate with another one of the virtual machines through the first service machine.
Optionally, the first service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
Optionally, the first service module is configured to provide a virtualized function.
Optionally, the processing system further includes the virtual switch.
Optionally, the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
Optionally, the first communication interface is configured for communication with the virtual switch through a first trunk, and the second communication interface is configured for communication with the first service switch through a second trunk.
Optionally, the processing system further includes: a second service machine having a second service module; and a second service switch; wherein the second service machine and the second service switch are configured for logically coupling between the plurality of virtual machines and the virtual switch.
Optionally, the first service machine, the first service switch, the second service machine, and the second service switch are coupled serially in a logical sense.
Optionally, the service machine is configured to map packets into different network segments based on packet destinations.
A data center includes the processing system, an additional processing system, and a physical switch, wherein the processing system and the additional processing system are coupled to the physical switch, and wherein the additional processing system comprises: a second service machine having a second service module; and a second service switch; wherein the second service machine and the second service switch are configured for logically coupling between an additional plurality of virtual machines and an additional virtual switch.
A method of implementing a processing system includes: providing a first service machine having a first service module; providing a first service switch; and logically coupling the first service machine and the first service switch between a plurality of virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the service switch.
Optionally, the first communication interface is configured for communication with the virtual switch.
Optionally, the first service switch comprises a third communication interface configured for communication with the plurality of virtual machines
Optionally, the method further includes providing VM-based network segments at the first service switch.
Optionally, the VM-based network segments correspond with the plurality of virtual machines, respectively.
Optionally, the virtual switch is configured to provide original network segments, and wherein the method further comprises providing a mapping at the first service machine for mapping the original network segments and the VM-based network segments.
Optionally, at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
Optionally, the first service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
Optionally, the first service module is configured to provide a virtualized function.
Optionally, the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
Optionally, the act of logically coupling the first service machine and the first service switch between the plurality of virtual machines and the virtual switch comprises communicatively coupling the first service machine with the virtual switch through a first trunk, and communicatively coupling the first service machine with the first service switch through a second trunk.
Optionally, the method further includes: providing a second service machine having a second service module; providing a second service switch; and logically coupling the second service machine and the second service switch between the plurality of virtual machines and the virtual switch.
Optionally, the first service machine, the first service switch, the second service machine, and the second service switch are coupled serially in a logical sense.
Optionally, the method further includes configuring the service machine to map packets into different network segments based on packet destinations.
A processing system includes: a service module; a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with a plurality of virtual machines; a second communication interface for communication with the virtual switch; wherein the service module, the first communication interface, and the second communication interface are parts of a service machine; wherein the first communication interface is associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and wherein the second communication interface is associated with original network segments at the virtual switch.
Optionally, the service machine comprises a mapping for mapping the original network segments and the VM-based network segments.
Optionally, at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
Optionally, the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
Optionally, the service module is configured to provide a virtualized function.
Optionally, the processing system further includes the virtual switch.
Optionally, the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
Optionally, the first communication interface is configured for communication with the virtual switch through a first trunk, and the second communication interface is configured for communication with the virtual switch through a second trunk.
Optionally, the service machine is configured to map packets into different network segments based on packet destinations.
A data center includes the processing system, an additional processing system, and a physical switch, wherein the processing system and the additional processing system are coupled to the physical switch, and wherein the additional processing system comprises: an additional service module; a third communication interface for communication with an additional virtual switch, the additional virtual switch configured for communicating with an additional plurality of virtual machines; and a fourth communication interface for communication with the additional virtual switch; wherein the additional service module, the third communication interface, and the fourth communication interface are parts of an additional service machine.
A method of implementing a processing system includes: providing a service machine having a service module, a first communication interface, and a second communication interface, wherein the first communication interface is configured for communication with a virtual switch, and wherein the second communication interface is configured for communication with the virtual switch, the virtual switch configured for communicating with a plurality of virtual machines; and logically coupling the service machine to the virtual switch by: associating the first communication interface with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and associating the second communication interface with original network segments at the virtual switch.
Optionally, the method further includes providing the VM-based network segments at the virtual switch.
Optionally, the method further comprises providing a mapping at the service machine for mapping the original network segments and the VM-based network segments.
Optionally, at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
Optionally, the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
Optionally, the service module is configured to provide a virtualized function.
Optionally, the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
Optionally, the act of logically coupling the service machine and the virtual switch comprises communicatively coupling the service machine with the virtual switch through a first trunk, and communicatively coupling the service machine with the virtual switch through a second trunk.
Optionally, the method further includes configuring the service machine to map packets into different network segments based on packet destinations.
Other and further aspects and features will be evident from reading the following detailed description of the embodiments.
The drawings illustrate the design and utility of embodiments, in which similar elements are referred to by common reference numerals. These drawings are not necessarily drawn to scale. In order to better appreciate how the above-recited and other advantages and objects are obtained, a more particular description of the embodiments will be rendered, which are illustrated in the accompanying drawings. These drawings depict only typical embodiments and are not therefore to be considered limiting of its scope.
Various embodiments are described hereinafter with reference to the figures. It should be noted that the figures are not drawn to scale and that elements of similar structures or functions are represented by like reference numerals throughout the figures. It should also be noted that the figures are only intended to facilitate the description of the embodiments. They are not intended as an exhaustive description of the invention or as a limitation on the scope of the invention. In addition, an illustrated embodiment needs not have all the aspects or advantages shown. An aspect or an advantage described in conjunction with a particular embodiment is not necessarily limited to that embodiment and can be practiced in any other embodiments even if not so illustrated, or not so explicitly described.
In a virtualized processing system, each physical server hosts one or more virtual switches and multiple user virtual machines (VMs) that connect to the virtual switches. Multiple broadcast domains (network segments) may be configured on a virtual switch. The user VMs on the same network segment may communicate to one another through the virtual switch. Virtualized network function/service may run on service VMs (service machines). These service machines may connect on the same virtual switch as other user VMs. However, without SDN support on the virtual switch, the communication between two user VMs on the same network segment will not goes through the service machine.
To illustrate the above point, refer to
In the setup shown in
Two network segments, Seg1 102 and Seg2 103, are configured on the virtual switch 100. Accordingly, the virtual switch 100 has the same or similar set up as that shown in
As shown in
As discussed before with reference to
On the service machine 200, two network segments, Seg1 and Seg2 206, are configured on the communication interface on which trunk 201 connects. This ensures that Seg1 and Seg2 206 have the same network connectivity as the Seg1 102 and Seg2 103 on the virtual switch 100. Also, on the service machine 200, five network segments, S1, S2, S3, S4, and S5 205, are configured on the communication interface on which trunk 202 connects. The network segments 205 correspond (e.g., match) the configuration of the network segments 301 on the service switch 300. This ensures that each VM 400 can reach the network segment 205 on the service machine 200. In some cases, the service machine 200 may be configured to map packets into different network segments based on packet destinations. In other cases, the mapping may be based on other parameter(s).
Since the user VM11 and the user VM12 used to connect to Seg1 102 on the virtual switch 100, segments S1 and S2 at the service switch (which corresponds with the VM11 and VM!2) are related to Seg1 on the service machine 200. Similarly segments S3, S4 and S5 are related to Seg2 on the service machine 200. The service machine 200 is configured to provide this mapping relationship that maps the VM-based network segments with the original network segments. Based on this mapping, packet is labeled with the corresponding tag when it is sent to certain segment. For example, packets may be tagged by the service switch 300, the virtual switch 100, or both. In some cases, the service machine 200 may also be configured to tag packets and/or to modify tags of packets. By means of non-limiting examples, the VM-based network segments may be based on a VLAN, a bridge, a VMware port group.
As shown in
Two packet flow examples will now be described to illustrate how the processing system of
A server on the Internet returns a packet, and the return packet first reaches the default gateway. The return packet then reaches segment Seg1 102 at the original virtual switch 100 through trunk connection 101, as represented by arrow 504. The packet is forwarded to Seg1 on the service machine 200 as represented by arrow 505. The return packet goes through the service module 204 as represented by arrow 506, where one or more service(s) is provided for the return packet. The return packet is then transmitted on segment S2 and reaches the user VM12, as represented by arrow 507.
As shown in the above examples, through the service switch 300 and the service machine 200, the desired service(s) is inserted to the packet path between the user VM12 and the Internet.
The processing system of
In the configuration shown in
In some embodiments, the processing system of
The method may also include creating VM-based network segments on the service switch 300, which correspond with the plurality of user VMs 400. The method may also include providing a mapping (e.g., a mapping module) at the service machine 200 for mapping original network segments associated with the virtual switch 100, with the VM-based network segments. The VM-based network segments may be based on VLAN(s), bridge(s), VMware port group(s), etc. The method may also include configuring the service machine 200 to map packets into different network segments based on packet destinations. In some embodiments, a packet mapping configurator may be provided to configure the service machine 200 so that it can map packets into different network segments based on the packet destinations.
As shown in
Private VLAN may be available on some hardware switches and virtual switches. In some cases, a private VLAN configuration may contain the definition of several VLAN/segments. For example, a private VLAN implementation (such as that on VMware vSphere Distributed Switch (VDS)) may include:
-
- Primary PVLAN: VMs in this segment can communicate to outside world, and VMs in the Secondary PVLANs.
- Isolated Secondary PVLAN: VMs in this VLAN are isolated to each other. They only can communicate to Primary PVLAN.
- Shared Secondary PVLAN: VMs in this VLAN can communicate to Primary PVLAN and VMs in the same Secondary PVLAN.
In some cases, only the primary PVLAN and the isolated Secondary PVLAN are configured to achieve the desired service(s).
Assume originally user VMs connect to Seg1 102 and Seg2 103 on the virtual switch 100, like that shown in
To match the segment configuration on the service switch 300, four network segments, Seg1, Iso1, Seg2, and Iso2 205, are created on the trunk interface (connecting to trunk 202) on the service VM 200. Only two segments, Seg1 and Seg2 206, are created on the trunk interface (connecting to trunk 201) at the service VM 200.
Two packet flow examples will now be described to illustrate how services can be inserted with this deployment. In the first example, the user VM12 sends a packet to and receives a packet from the Internet. When the user VM12 sends the packet to the Internet, it first sends the packet to the default gateway of its network, then the default gateway sends the packet to other nodes on the Internet. In this deployment example, the default gateway can be reached through the trunk 101. It is assumed that all the ports on virtual switches and the VM12 have learned the MAC address of the interface on the default gateway. The packet leaves the VM12 and enters segment Iso1 302 on the service switch 300. Based on MAC lookup, the service switch 300 forwards the packet through the trunk 202, and the packet reaches segment Iso1 on the service VM 200. The packet path is represented by arrow 500. Inside the service VM 200, one or more desired service(s) is applied on the packet, and the packet is then forwarded to segment Seg1 206. The service VM 200 then transmits the packet through the trunk 201, and the packet reaches segment Seg1 102. This path is represented by arrow 502. At last the packet is sent to the default gateway through the trunk 101, as represented by arrow 503.
A node on the Internet sends a return packet. The return packet from the Internet first reaches the default gateway. Then it reaches segment Seg1 102 through the trunk connection 101, as represented by arrow 504. The packet is then forwarded to Seg1 on the service VM 200, as represented by arrow 505. The packet goes through the service module 204, wherein one or more desired service(s) is performed, as represented by arrow 506. The packet is then transmitted on segment S2 205, on the service VM 200, and the packet reaches the VM12, as represented by arrow 507. Accordingly, through the service switch 300 and the service VM 200, the required service(s) is inserted to the packet path between the user VM12 and the Internet.
The illustrated system can also insert service(s) into the communication path between two user VMs on the same network segment, such as the communication path between the user VM22 and the user VM23. In the original deployment shown in
Since the user VM23 and the user VM22 are on isolated secondary PVLAN 304, they cannot directly communicate on the service switch 300. Instead, the user VM23 sends the packet to Iso2 304, and the packet is then forwarded to segment Iso2 on the service VM 200, as represented by arrow 600. Based on the service rule configuration, the service module 204 forwards the packet to Seg2 on the service VM 200. Then the packet is sent to the user VM22 through the segment Seg2 303. Through the configuration of the private VLAN on the service switch 300, the communication between two user VMs can go through the service VM 200, which provides the desired service.
The service machine 200 is connected to the virtual switch 100 through a trunk 201 and a trunk 202. In the illustrated embodiments, the service machine 200 has a first communication interface for communicating with the virtual switch 100 through the trunk 202, and a second communication interface for communicating with the virtual switch 100 through the trunk 201. In some cases, the first and second communication interfaces may be respective trunk ports. The trunk 201 is configured to communicate with data center network through the virtual switch 100, and the trunk 202 is configured to communicate with the VMs 400 (i.e., VM11, VM12, VM21, VM22 and VM23 in the example) through the virtual switch 100.
As discussed with reference to
At the service machine 200, two network segments, Seg1 and Seg2 206, are configured on the communication interface on which the trunk 201 connects. This ensures that Seg1 and Seg2 206 have the same network connectivity as the Seg1 102 and Seg2 103 on the virtual switch 100. Also, at the service machine 200, five network segments, S1, S2, S3, S4, and S5 205, are configured on the communication interface on which the trunk 202 connects. The network segments 205 at the service machine 200 correspond (e.g., match) the configuration with the network segments on the service virtual switch 100. This ensures that the user VMs 400 can reach the network segments 205 at the service machine 200. In some cases, the service machine 200 may be configured to map packets into different network segments based on packet destinations. In other cases, the mapping may be based on other parameter(s).
Since the user VM11 and the user VM12 were previously connected to Seg1 102 on the virtual switch 100 (as described with reference to
As shown in
Two packet flow examples will now be described to illustrate how the processing system of
A node on the Internet sends a return packet, and the return packet first reaches the default gateway. Then the return packet reaches segment Seg1 102 through the trunk 101, as represented by arrow 504. The return packet is then forwarded to Seg1 at the service machine 200, as represented by arrow 505. The packet goes through the service module 204, where one or more services are provided to process the packet, as represented by arrow 506. The packet is then transmitted on segment S2 and reaches VM12, as represented by arrow 507. Accordingly, through the virtual switch 100 and the service machine 200, the desired service(s) is provided to the packet path between the user VM12 and the Internet.
In another example, one or more desired services are provided between two user VMs on the same network segment, such as between the user VM22 and the user VM23. In the original configuration shown in
In some embodiments, isolation for two or more user VMs in the system of
In some embodiments, the processing system of
The act of logically coupling may include communicatively coupling the service machine 200 with the service switch 300 through a first trunk, and communicatively coupling the service machine 200 with the service switch 300 through a second trunk.
The method may also include providing VM-based network segments at the virtual switch 100, which correspond with the plurality of user VMs 400. The method may also include providing a mapping (e.g., a mapping module) at the service machine 200 for mapping original network segments associated with the virtual switch 100, with the VM-based network segments. The VM-based network segments may be based on VLAN(s), bridge(s), VMware port group(s), etc. The method may also include configuring the service machine 200 to map packets into different network segments based on packet destinations. In some embodiments, a packet mapping configurator may be provided to configure the service machine 200 so that it can map packets into different network segments based on the packet destinations.
In particular, the processing system includes the original virtual switch 100 and the user VMs 400. By means of non-limiting examples, the virtual switch 100 may comprise a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch. The virtual switch 100 is configured on a physical server. The virtual switch 100 connects to the rest of data center network through an uplink 101. Two network segments, Seg1 102 and Seg2 103, are configured on the virtual switch 100.
The processing system also includes a first service VM (service machine) 200 with a service module 204, and a first service virtual switch (service switch) 300. The processing system also includes a second service VM (service machine) 400 with a service module 402, and a second service virtual switch (service switch) 500. These components 200, 300, 400, 500 are communicatively coupled to one another serially (e.g., in a logical sense) through trunks 201, 202, 203, 602. As shown in the figure, the service machine 200 connects to the virtual switch 100 through trunk 201. The service switch 300 connects to the service machine 200 through another trunk 202. The service machine 400 connects to the service switch 300 through trunk 203. The service switch 500 connects to the service machine 400 through trunk 602. The user VMs 400 (e.g., VM11, VM12, VM21, VM22 and VM23) connect to service switch 500.
On the service machine 200, two network segments, Seg1 and Seg2 206, are configured on the interface on which the trunk 201 connects. This ensures that Seg1 and Seg2 206 have the same network connectivity as the Seg1 102 and Seg2 103 on the virtual switch 100. On the service machine 200, five network segments, S1, S2, S3, S4, and S5 205 are configured on the interface on which the trunk 202 connects. These network segments correspond (e.g., matches) the configuration of the network segments at the service switch 300. In some cases, the service machine 200 may be configured to map packets into different network segments based on packet destinations. In other cases, the mapping may be based on other parameter(s).
On the service switch 300, five network segments, S1, S2, S3, S4 and S5 are configured to correspond with the segments S1, S2, S3, S4 and S5 in the service machine 200 and the service machine 400, so that they are the same segments.
On the service machine 400, five network segments, S1, S2, S3, S4, and S5 401 are configured on the interfaces on which trunk 203 and 602 connect. These segments correspond (e.g., match) with the configuration of the network segments on the service switch 500. In some cases, the service machine 400 may be configured to map packets into different network segments based on packet destinations. In other cases, the mapping may be based on other parameter(s).
In the original deployment shown in
Since the user VM11 and the user VM12 used to connect to Seg1 102 on the virtual switch 100, segments S1 and S2 are related to Seg1 on the service machine 200. Similarly segments S3, S4 and S5 are related to Seg2 on the service machine 200. The service machine 200, the service machine 400, the service switch 300, the service switch 500, or any combination of the foregoing, is configured to provide this mapping relationship that maps the VM-based network segments with the original network segments. Based on this mapping, packet is labeled with the corresponding tag when it is sent to certain segment. For example, packets may be tagged by the service switch 500, the service switch 300, the virtual switch 100, or all. In some cases, the service machine 200 and the service machine 400 may also be configured to tag packets and/or to modify tags of packets. By means of non-limiting examples, the VM-based network segments may be based on a VLAN, a bridge, a VMware port group.
As shown in
Two packet flow examples will now be described to illustrate how the processing system of
A node on the Internet sends a return packet to the processing system. The return packet from the Internet first reaches the default gateway. Then it reaches segment Seg1 102 through trunk connection 101, as represented by arrow 706. The return packet is then forwarded to Seg1 on the service machine 200, as represented by arrow 707. The return packet goes through the service module 204 wherein one or more service(s) is provided to process the packet, as represented by arrow 708. Then the service machine 200 transmits the return packet to the service switch 300 through the segment S2, as represented by arrow 709. Then the service switch 300 sends the return packet to the service machine 400 through the segment S2, as represented by arrow 710. The return packet is then transmitted on segment S2 in the service switch 500, and reaches the user VM12, as represented by arrow 711. Accordingly, through the service switches 300, 500 and service machines 200, 400, the desired service(s) is inserted to the packet path between the user VM12 and the Internet.
The processing system can also insert multiple services in the communication path between two user VMs on the same network segment, such as in the communication path between the user VM22 and the user VM23. In the original deployment shown in
In the deployment shown in
Through the configuration of the service switches 300, 500 and VM-based network segments, the communication between two user VMs can go through service machines that provide the desired services.
In some embodiments, isolation for two or more user VMs in the system of
In some embodiments, the processing system of
The method may also include creating VM-based network segments on the first service switch, the second service switch, the first service machine, the second service machine, or any combination of the foregoing. The created VM-based network segments correspond with the plurality of user VMs 400. The method may also include providing a mapping (e.g., a mapping module) at the first service machine, the second service machine, or both, for mapping original network segments associated with the virtual switch 100, with the VM-based network segments. The VM-based network segments may be based on VLAN(s), bridge(s), VMware port group(s), etc. The method may also include configuring the first and second service machines to map packets into different network segments based on packet destinations. In some embodiments, a packet mapping configurator may be provided to configure the first and second service machines so that it can map packets into different network segments based on the packet destinations.
In some embodiments, each of the processing systems of
As shown in the example above, the processing system for service insertion in the server 900a can be replicated to other physical servers in one data center, like server 900b and server 900c. Thus the service can be provided for all user VMs in the data center. In the example shown in
Specialized Processing Architecture
In some embodiments, one or more virtual machine(s), the service machine 200, the service switch 300, or any combination of the foregoing may be implemented using a specialized processing system.
As shown in
The processing system 1200 also includes a main memory 1206, such as a random access memory (RAM) or other dynamic storage device, coupled to the bus 1202 for storing information and instructions to be executed by the processor 1204. The main memory 1206 also may be used for storing temporary variables or other intermediate information during execution of instructions to be executed by the processor 1204. The processing system 1200 further includes a read only memory (ROM) 1208 or other static storage device coupled to the bus 1202 for storing static information and instructions for the processor 1204. A data storage device 1210, such as a magnetic disk or optical disk, is provided and coupled to the bus 1202 for storing information and instructions.
The processing system 1200 may be coupled via the bus 1202 to a display 1212, such as a cathode ray tube (CRT) or a LCD monitor, for displaying information to a user. An input device 1214, including alphanumeric and other keys, is coupled to the bus 1202 for communicating information and command selections to processor 1204. Another type of user input device is cursor control 1216, such as a mouse, a trackball, or cursor direction keys for communicating direction information and command selections to processor 1204 and for controlling cursor movement on display 1212. This input device typically has two degrees of freedom in two axes, a first axis (e.g., x) and a second axis (e.g., y), that allows the device to specify positions in a plane.
The processing system 1200 may be used for performing various functions in accordance with the embodiments described herein. According to one embodiment, such use is provided by the processing system 1200 in response to processor 1204 executing one or more sequences of one or more instructions contained in the main memory 1206. Such instructions may be read into the main memory 1206 from another processor-readable medium, such as storage device 1210. Execution of the sequences of instructions contained in the main memory 1206 causes the processor 1204 to perform the process steps described herein. One or more processors in a multi-processing arrangement may also be employed to execute the sequences of instructions contained in the main memory 1206. In alternative embodiments, hard-wired circuitry may be used in place of or in combination with software instructions to implement features of the embodiments described herein. Thus, embodiments described herein are not limited to any specific combination of hardware circuitry and software.
The term “processor-readable medium” as used herein refers to any medium that participates in providing instructions to the processor 1204 for execution. Such a medium may take many forms, including but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media includes, for example, optical or magnetic disks, such as the storage device 1210. A non-volatile medium may be considered to be an example of a non-transitory medium. Volatile media includes dynamic memory, such as the main memory 1206. A volatile medium may be considered to be another example of a non-transitory medium. Transmission media includes coaxial cables, copper wire and fiber optics, including the wires that comprise the bus 1202. Transmission media can also take the form of acoustic or light waves, such as those generated during radio wave and infrared data communications.
Common forms of processor-readable media include, for example, a floppy disk, a flexible disk, hard disk, magnetic tape, or any other magnetic medium, a CD-ROM, any other optical medium, punch cards, paper tape, any other physical medium with patterns of holes, a RAM, a PROM, and EPROM, a FLASH-EPROM, any other memory chip or cartridge, a carrier wave as described hereinafter, or any other medium from which a processor can read.
Various forms of processor-readable media may be involved in carrying one or more sequences of one or more instructions to the processor 1204 for execution. For example, the instructions may initially be carried on a magnetic disk of a remote computer. The remote computer can load the instructions into its dynamic memory and send the instructions over a telephone line using a modem. A modem local to the processor system 1200 can receive the data on the telephone line and use an infrared transmitter to convert the data to an infrared signal. An infrared detector coupled to the bus 1202 can receive the data carried in the infrared signal and place the data on the bus 1202. The bus 1202 carries the data to the main memory 1206, from which the processor 1204 retrieves and executes the instructions. The instructions received by the main memory 1206 may optionally be stored on the storage device 1210 either before or after execution by the processor 1204.
The processor system 1200 also includes a communication interface 1218 coupled to the bus 1202. The communication interface 1218 provides a two-way data communication coupling to a network link 1220 that is connected to a local network 1222. For example, the communication interface 1218 may be an integrated services digital network (ISDN) card or a modem to provide a data communication connection to a corresponding type of telephone line. As another example, the communication interface 1218 may be a local area network (LAN) card to provide a data communication connection to a compatible LAN. Wireless links may also be implemented. In any such implementation, the communication interface 1218 sends and receives electrical, electromagnetic or optical signals that carry data streams representing various types of information.
The network link 1220 typically provides data communication through one or more networks to other devices. For example, the network link 1220 may provide a connection through local network 1222 to a host computer 1224 or to equipment 1226 such as a radiation beam source or a switch operatively coupled to a radiation beam source. The data streams transported over the network link 1220 can comprise electrical, electromagnetic or optical signals. The signals through the various networks and the signals on the network link 1220 and through the communication interface 1218, which carry data to and from the processor system 1200, are exemplary forms of carrier waves transporting the information. The processor system 1200 can send messages and receive data, including program code, through the network(s), the network link 1220, and the communication interface 1218.
In some embodiments, the processor system 1200 may be a part of a physical server or computer that is specifically configured to implement one or more features described herein. For example, the service VM(s) and service switch(es) described herein may be virtual components implemented on such physical server. However, it should be noted that the configuration of the server or computer is not necessarily limited to the example described. In other embodiments, the service VM(s) and the service switch(es) described herein may be created and configured on any physical server as long as the server supports virtualization.
It should be noted that when a “packet” is described in this application, it should be understood that it may refer to the original packet that is transmitted from a node, or a copy of it.
It should be noted that the terms “first”, “second”, etc., are used to refer to different things, and do not necessarily refer to the order of things.
Although particular embodiments have been shown and described, it will be understood that they are not intended to limit the claimed inventions, and it will be obvious to those skilled in the art that various changes and modifications may be made without departing from the spirit and scope of the claimed inventions. The specification and drawings are, accordingly, to be regarded in an illustrative rather than restrictive sense. The claimed inventions are intended to cover alternatives, modifications, and equivalents.
Claims
1. A processing system, comprising:
- a service module;
- a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with a plurality of virtual machines;
- a second communication interface for communication with the virtual switch;
- wherein the service module, the first communication interface, and the second communication interface are parts of a service machine;
- wherein the first communication interface is associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and
- wherein the second communication interface is associated with original network segments at the virtual switch.
2. The processing system of claim 1, wherein the service machine comprises a mapping for mapping the original network segments and the VM-based network segments.
3. The processing system of claim 1, wherein at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
4. The processing system of claim 1, wherein the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
5. The processing system of claim 1, wherein the service module is configured to provide a virtualized function.
6. The processing system of claim 1, further comprising the virtual switch.
7. The processing system of claim 6, wherein the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
8. The processing system of claim 1, wherein the first communication interface is configured for communication with the virtual switch through a first trunk, and the second communication interface is configured for communication with the virtual switch through a second trunk.
9. The processing system of claim 1, wherein the service machine is configured to map packets into different network segments based on packet destinations.
10. A data center having the processing system of claim 1, an additional processing system, and a physical switch, wherein the processing system and the additional processing system are coupled to the physical switch, and wherein the additional processing system comprises:
- an additional service module;
- a third communication interface for communication with an additional virtual switch, the additional virtual switch configured for communicating with an additional plurality of virtual machines; and
- a fourth communication interface for communication with the additional virtual switch;
- wherein the additional service module, the third communication interface, and the fourth communication interface are parts of an additional service machine.
11. A method of implementing a processing system, comprising:
- providing a service machine having a service module, a first communication interface, and a second communication interface, wherein the first communication interface is configured for communication with a virtual switch, and wherein the second communication interface is configured for communication with the virtual switch, the virtual switch configured for communicating with a plurality of virtual machines; and
- logically coupling the service machine to the virtual switch by: associating the first communication interface with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and associating the second communication interface with original network segments at the virtual switch.
12. The method of claim 11, further comprising providing the VM-based network segments at the virtual switch.
13. The method of claim 11, wherein the method further comprises providing a mapping at the service machine for mapping the original network segments and the VM-based network segments.
14. The method of claim 11, wherein at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
15. The method of claim 11, wherein the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
16. The method of claim 11, wherein the service module is configured to provide a virtualized function.
17. The method of claim 11, wherein the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
18. The method of claim 11, wherein the act of logically coupling the service machine and the virtual switch comprises communicatively coupling the service machine with the virtual switch through a first trunk, and communicatively coupling the service machine with the virtual switch through a second trunk.
19. The method of claim 11, further comprising configuring the service machine to map packets into different network segments based on packet destinations.
Type: Application
Filed: Sep 9, 2019
Publication Date: Jan 2, 2020
Applicant: HILLSTONE NETWORKS CORP. (SUNNYVALE, CA)
Inventors: Dongyi Jiang (San Jose, CA), Jin Shang (Saratoga, CA), Ye Zhang (Sunnyvale, CA), Juxi Li (San Jose, CA), Hua Ji (Cupertino, CA)
Application Number: 16/565,465