Service-function chaining using extended service-function chain proxy for service-function offload
US-2018295053-A1 · Oct 11, 2018 · US
US10855588B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10855588-B2 |
| Application number | US-201816230668-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 21, 2018 |
| Priority date | Dec 21, 2018 |
| Publication date | Dec 1, 2020 |
| Grant date | Dec 1, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques are described for facilitating flow symmetry using a scalable service platform that anchors the service chain. The scalable service platform may facilitate flow symmetry and, at least in some cases, flow stickiness for a first packet flow (a “forward packet flow” and a second, related packet flow (a “reverse packet flow”) both traversing the service chain in the forward and reverse directions, respectively. For example, a virtualized computing infrastructure may deploy a scalable service platform to perform load balancing of multiple forward packet flows, received from the gateway, among multiple parallel service instances for an ingress service in a service chain. For each corresponding reverse packet flows for the multiple forward packet flows, the scalable service platform load balances the reverse packet flow to the service instance for the egress service in the service chain that is applied to the corresponding forward packet flow.
Opening claim text (preview).
What is claimed is: 1. A system comprising: a network controller for a virtualized computing infrastructure, wherein the network controller is configured to: receive a request for a service chain comprising one or more service instances for the service chain; and install, to a server of the virtualized computing infrastructure, an egress service instance of the one or more service instances for the service chain; and a scalable service platform, wherein the scalable service platform comprises one or more virtual routers executing on a set of one or more servers, wherein the one or more virtual routers are configured to receive a packet for a forward packet flow from the server hosting the egress service instance, wherein the packet comprises an outer Internet Protocol (IP) header comprising an IP address of the server hosting the egress service instance, wherein the one or more virtual routers are configured to create, in response to receiving the packet for the forward packet flow and based on the outer IP header of the packet for the forward packet flow, a flow table entry for a reverse packet flow corresponding to the forward packet flow, wherein the flow table entry specifies the IP address of the server hosting the egress service instance as a next hop for the reverse packet flow, and wherein the one or more virtual routers are configured to forward, based on the flow table entry, the reverse packet flow to the server hosting the egress service instance. 2. The system of claim 1 , wherein the network controller is configured to: install the one or more service instances for the service chain to one or more servers of the virtualized computing infrastructure, the one or more service instances including the egress service instance; install, to the scalable service platform, a first service instance for an ingress of the service chain; and install, to the scalable service platform, a second service instance for an egress of the service chain, wherein the first service instance and second service instance operate as endpoints for the service chain to anchor packet flows mapped to the service chain. 3. The system of claim 1 , wherein the network controller is configured to install, to the scalable service platform, a second service instance for an egress of the service chain, and wherein the one or more virtual routers are configured to create a flow table entry for the reverse packet flow by identifying a flow table for a routing instance that implements the second service instance and creating the flow table entry in the identified flow table. 4. The system of claim 1 , wherein the network controller is configured to: install, to the scalable service platform, a first service instance for an ingress of the service chain; and configure the first service instance with a virtual network interface having a virtual network address, wherein the scalable service platform receives the forward packet flow, wherein the forward packet flow is tunneled to the virtual network address. 5. The system of claim 4 , wherein the network controller is configured to send a configuration message to a gateway for the virtualized computing infrastructure to program, in the gateway, the virtual network address as a next hop address for packet flows to be mapped to the service chain. 6. The system of claim 1 , wherein the network controller is configured to, in response to detecting a load on the scalable service platform that exceeds a threshold, add an additional virtual router executing on an additional server to scale up the scalable service platform. 7. The system of claim 1 , further comprising: wherein the network controller is configured to install, to servers of the virtualized computing infrastructure, a plurality of parallel ingress service instances of the one or more service instances for the service chain, wherein a virtual router of the one or more virtual routers is configured to, in response to receiving a packet of the forward packet flow, select one of the parallel ingress service instances and forward the packet to a server that hosts the selected parallel ingress service instance, and wherein the virtual router is configured to receive the reverse packet from the server that hosts the selected parallel ingress service instance. 8. The system of claim 7 , wherein the network controller is configured to install, to the virtual router, a first service instance for the ingress of the service chain, wherein the virtual router is hosted by a server of the set of one or more servers, and wherein the virtual router is configured to generate and send, to the server that hosts the selected parallel ingress service instance, a tunnel packet having a source network address that is a network address of the server hosting the virtual router. 9. The system of claim 1 , wherein the network controller is configured to: install the one or more service instances for the service chain to one or more servers of the virtualized computing infrastructure, the one or more service instances including the egress service instance; install, to the scalable service platform, a first service instance for an ingress of the service chain; and install, to the scalable service platform, a second service instance for an egress of the service chain, wherein the first service instance and the second service instance each map to a different port-tuple object each defining at least one port. 10. A method comprising: receiving, by a network controller for a virtualized computing infrastructure, a request for a service chain comprising one or more service instances for the service chain; installing, by the network controller to a server of the virtualized computing infrastructure, an egress service instance of the one or more service instances for the service chain; installing, by the network controller, the one or more service instances for the service chain to one or more servers of the virtualized computing infrastructure, the one or more service instances including the egress service instance; installing, by the network controller to a scalable service platform comprising one or more virtual routers executing on a set of one or more servers, to a first server of the one or more servers of the scalable service platform, a first service instance for an ingress of the service chain; installing, by the network controller to a second server of the one or more servers of the scalable service platform, a second service instance for an egress of the service chain, wherein the first service instance and the second service instance operate as endpoints for the service chain to anchor packet flows mapped to the service chain, wherein the second service instance is configured to receive a packet for a forward packet flow from the server hosting the egress service instance, wherein the packet comprises an outer Internet Protocol (IP) header comprising an IP address of the server hosting the egress service instance; creating, in response to receiving the packet for the forward packet flow and based on the outer IP header of the packet for the forward packet flow, a flow table entry for a reverse packet flow corresponding to the forward packet flow, wherein the flow table entry specifies the IP address of the server hosting the egress service instance as a next hop for the reverse packet flow; and forwarding, by the second service instance and based on the flow table entry, the reverse packet flow to the server hosting the egress service instance. 11. The method of claim 10 , further comprising: forwarding, by the first service instance and based on a flow table entry for the forward packet fl
Address table lookup; Address filtering · CPC title
Flow based routing · CPC title
using an overlay routing layer · CPC title
Aggregation of resource allocation or reservation requests · CPC title
Virtual private networks · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.