Private virtual local area network isolation
US-9363207-B2 · Jun 7, 2016 · US
US9602335B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9602335-B2 |
| Application number | US-201314072325-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 5, 2013 |
| Priority date | Jan 22, 2013 |
| Publication date | Mar 21, 2017 |
| Grant date | Mar 21, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Embodiments of the invention relate to providing network independent network interfaces. One embodiment includes creating a root interface in a first device in a network system. Virtual network interface cards (vNICs) are added to the root interface. The first device executes network services on the root interface. The root interface is a single access point for accessing a plurality of underlying networks.
Opening claim text (preview).
What is claimed is: 1. A method comprising: creating a root interface in a first device in a network system; adding virtual network interface cards (vNICs) to the root interface; and using a bridge device in support of a kernel bridge infrastructure, the kernel bridge infrastructure being modified using netfilter hooks to prevent forwarding of broadcast packets between bridge ports and to set a source media access control (MAC) address of an egress packet to a corresponding MAC address of a vNIC; wherein the first device executes network services on the root interface, network operations are executed on the root interface for the first device based on receiving packets through the vNICs, and the root interface is a single access point for accessing a plurality of underlying networks. 2. The method of claim 1 , wherein the root interface is assigned network properties and comprises a logical parent interface for all vNICs. 3. The method of claim 2 , wherein processing is performed for the operating system (OS) of the first device as if the received packets are directly received on the root interface to enable the first device to perform the network operations independent of vNICs connectivity; and each of the vNICs comprise child interfaces of the root interface. 4. The method of claim 3 , further comprising: connecting a vNIC added to the root interface to any virtual switch (VS) or VS port in the network system, wherein the vNICs connectivity is transparent to the underlying networks. 5. The method of claim 4 , further comprising: receiving a packet comprising an address; creating a table for mapping the address to vNICs; selecting a vNIC for communicating to an underlying network based on a destination address; and forwarding broadcast packets generated in the root interface to child vNICs without forwarding broadcast packets between the child vNICs. 6. The method of claim 5 , wherein creating of the root interface comprises using a device driver, the device driver provides adding other vNICs as child interfaces to the root interface, a packet received on a child vNIC passes through the root device prior to reaching a networking stack of the OS. 7. The method of claim 6 , wherein creating of the root interface comprises: managing bridge module operations using a bridge utility tool; creating a bridge interface; adding and removing ports to and from the bridge interface, wherein the bridge interface acts as the root interface, and the vNICs are added as ports of the bridge module and are child interfaces to the root interface. 8. The method of claim 7 , wherein based on the logical relationship between the root interface and all of the child interfaces, tracking by the first device of the plurality of vNICs connectivity to the one or more underlying networks is unnecessary. 9. The method of claim 1 , wherein the first device is one of a virtual machine (VM), and a server with more than one network interfaces.
Address table lookup; Address filtering · CPC title
Network integration; Enabling network access in virtual machine instances · CPC title
Standardised network management protocols, e.g. simple network management protocol [SNMP] · CPC title
Virtual switches · CPC title
Hypervisor-specific management and integration aspects · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.