CA3074501C

Creating virtual networks spanning multiple public clouds

Abstract

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.

CA3074501C, drawing sheet 1
Sheet 1 of 23

Term

12 yearsleft in the term

Expires 1 October 2038.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

14 claims: 2 independent, 12 dependent

  1. 1
    A method of establishing a virtual network over a plurality of public cloud datacenters for a first entity, the method comprising:receiving data from the first entity identifying a set of locations of machines of the first entity outside of the public cloud datacenters to connect;configuring a set of forwarding elements, executing on a set of virtual machines that execute on a set of host computers, in first and second multi-tenant public cloud datacenters to implement a first virtual overlay wide area network (WAN) for the first entity, said first virtual overlay WAN (i) connecting each forwarding element to at least one other forwarding element through an overlay tunnel and (ii) spanning the first and second multi-tenant public cloud datacenters to connect the first entity’s locations identified in the data received from the first entity, each of a plurality of the first entity’s locations comprising a plurality of machines, wherein at least one of the forwarding elements in the set of forwarding elements is configured to establish a second virtual overlay WAN to connect a set of machines of a second entity outside of the public cloud datacenters;and forwarding, through the first virtual overlay WAN, data messages between machines of the first entity that reside outside of the first and second multi-tenant public cloud datacenters, said forwarding using a tenant identifier identifying the first entity as a tenant that uses the set of forwarding elements that implement the first virtual overlay WAN over toe first and second multi-tenant public cloud datacenters, wherein each of the first and second multi-tenant public cloud datacenters comprises host computers executing machines of a plurality of tenants of toe public cloud datacenter.
  2. 12
    A machine readable medium storing a program which when executed by at least one processing unit implements the method according to any one of claims 1 to 11.
  3. 13
    An electronic device comprising:a set of processing units;and a machine readable medium storing a program which when executed by at least one of the processing units implements the method according to any one of claims 1 to 11.
  4. 14
    A system comprising means for implementing the method according to any one of claims 1 to II.