Launching service applications using a virtual network management system
US-8954858-B2 · Feb 10, 2015 · US
US2016188359A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016188359-A1 |
| Application number | US-201615060758-A |
| Country | US |
| Kind code | A1 |
| Filing date | Mar 4, 2016 |
| Priority date | Apr 4, 2012 |
| Publication date | Jun 30, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A sense of location is provided for distributed virtual switch components into the service provisioning scheme to reduce latency observed in conducting policy evaluations across a network in a hybrid cloud environment. A management application in a first virtual network subscribes to virtual network services provided by a second virtual network. A first message is sent to the second virtual network, the first message comprising information configured to start a virtual switch in the second virtual network that switches network traffic for one or more virtual machines in the second virtual network that are configured to extend services provided by the first virtual network into the second virtual network. A second message is sent to the second virtual network, the second message comprising information configured to start a virtual service node in the second virtual network that provides network traffic services for the one or more virtual machines.
Opening claim text (preview).
What is claimed is: 1 . A method comprising: at a management application in a first virtual network comprising a first virtual service node, subscribing to virtual network services provided by a second virtual network; sending to the second virtual network a first message comprising information configured to start in the second virtual network a virtual switch that switches network traffic for one or more virtual machines in the second virtual network to extend services provided by the first virtual network into the second virtual network; and sending to the second virtual network a second message comprising information configured to start a second virtual service node in the second virtual network direct network traffic among virtual machines within the second virtual network based on service policies. 2 . The method of claim 1 , further comprising assigning to the second virtual network an identifier configured to identify resources in the second virtual network that are associated with the first virtual network. 3 . The method of claim 2 , wherein the identifier is configured to indicate a location of the resources as being in the second virtual network. 4 . The method of claim 2 , further comprising associating the identifier with the virtual service node and the virtual switch in order for the virtual switch to direct network traffic to the virtual service node. 5 . The method of claim 1 , further comprising: routing by the virtual switch network traffic associated with the one or more virtual machines to the virtual service node; and providing by the virtual service node network traffic services for the associated network traffic. 6 . The method of claim 1 , further comprising: defining and storing information representing a plurality of service policies; and defining and storing information representing a plurality service profiles comprising one or more identifiers for corresponding service policies for one or more virtual service nodes configured to provide network traffic services. 7 . The method of claim 6 , further comprising: generating information representing a port profile comprising one or more service profile identifiers and an identifier for the virtual service node, thereby assigning one or more service profiles to the port profile; assigning a virtual network port to a virtual machine running in the second virtual network; associating the port profile with the virtual network port; and routing, by the virtual switch, network traffic associated with the virtual machine to the virtual service node based on the virtual service node identifier. 8 . The method of claim 1 , wherein the virtual network services include firewall services and wide area application services. 9 . An apparatus comprising: one or more network interfaces configured to interface with a first virtual network; and a processor coupled to the one or more network interfaces, and configured to: subscribe to virtual network services provided by a second virtual network; send to the second virtual network a first message comprising information configured to start in the second virtual network a virtual switch that switches network traffic for one or more virtual machines in the second virtual network to extend services provided by the first virtual network into the second virtual network; and send to the second virtual network a second message comprising information configured to start a second virtual service node in the second virtual network direct network traffic among virtual machines within the second virtual network based on service policies. 10 . The apparatus of claim 9 , wherein the processor is further configured to assign to the second virtual network an identifier to identify resources in the second virtual network that are associated with the first virtual network, wherein the identifier is configured to indicate a location of the resources as being in the second virtual network. 11 . The apparatus of claim 10 , wherein the processor is further configured to associate the identifier with the virtual service node and the virtual switch in order for the virtual switch to direct network traffic to the virtual service node. 12 . The apparatus of claim 9 , wherein the processor is further configured to: define and store information representing a plurality of service policies; and define and store information representing a plurality service profiles comprising one or more identifiers for corresponding service policies for one or more virtual service nodes configured to provide network traffic services. 13 . The apparatus of claim 12 , wherein the processor is further configured to generate information representing a port profile comprising one or more service profile identifiers and an identifier for the virtual service node which assigns one or more service profiles to the port profile. 14 . The apparatus of claim 13 , wherein the processor is further configured to: assign a virtual network port to a virtual machine running in the second virtual network; and associate the port profile with the virtual network port in order for the virtual switch to route network traffic associated with the virtual machine to the virtual service node based on the virtual service node identifier. 15 . The apparatus of claim 9 , wherein the virtual network services include firewall services and wide area application services. 16 . One or more non-transitory computer readable storage media storing instructions that, when executed by a processor, cause the processor to: subscribe to virtual network services provided by a second virtual network; send to the second virtual network a first message comprising information configured to start in the second virtual network a virtual switch that switches network traffic for one or more virtual machines in the second virtual network to extend services provided by the first virtual network into the second virtual network; and send to the second virtual network a second message comprising information configured to start a second virtual service node in the second virtual network direct network traffic among virtual machines within the second virtual network based on service policies. 17 . The computer readable storage media of claim 16 , further comprising instructions that, when executed by a processor, cause the processor to assign to the second virtual network an identifier configured to identify resources in the second virtual network that are associated with the first virtual network, wherein the identifier is configured to indicate a location of the resources as being in the second virtual network. 18 . The computer readable storage media of claim 16 , further comprising instructions that, when executed by a processor, cause the processor to associate the identifier with the virtual service node and the virtual switch in order for the virtual switch to direct network traffic to the virtual service node. 19 . The computer readable storage media of claim 16 , further comprising instructions that, when executed by a processor, cause the processor to: define and store information representing a plurality of service policies; and define and store information representing a plurality service profiles comprising one or more identifiers for corresponding service policies for one or more virtual service nodes configured to provide network traffic services. 20 . The computer readable storage media of claim 16 , further comprising instruction
Hypervisor-specific management and integration aspects · CPC title
Hybrid transport · CPC title
in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title
Discovery or management of network topologies · CPC title
Network integration; Enabling network access in virtual machine instances · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.