EP4272402A1

Layer-2 networking span port in a virtualized cloud environment

Abstract

This record has no abstract on file.

EP4272402A1, drawing sheet 1
Sheet 1 of 25

Term

15.2 yearsto projected expiry

Projected expiry 24 November 2041, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 6 independent, 14 dependent

  1. 1
    Claims of equivalent WO 2022146589 A1 WHAT IS CLAIMED IS:1. A method comprising: generating, based on input of a customer, information indicating one or more criteria associated with copying frames sent in a Layer 2 virtual network and a destination to receive frame copies, wherein the Layer 2 virtual network is hosted on a physical network and comprises a plurality of Layer 2 compute instances, a plurality of Layer 2 virtual network interfaces, and a plurality of Layer 2 virtual switches;determining that the information is to be sent to a network virtualization device (NVD) of the physical network, wherein: the NVD hosts a Layer 2 virtual network interface of the plurality of Layer 2 virtual network interfaces and a Layer 2 virtual switch of the plurality of Layer 2 virtual switches, the Layer 2 virtual network interface and the Layer 2 virtual switch are associated with a Layer 2 compute instance of the plurality of Layer 2 compute instances, and the Layer 2 compute instance is hosted on a host machine of the physical network, the host machine and the NVD being communicatively coupled;and sending the information to the NVD.
  2. 3
    The method of any of claims 1-2, wherein the input of the customer indicates that the one or more criteria are to be applied to ingress traffic to the Layer 2 compute instance, and wherein the determining that the information is to be sent to the NVD comprises determining that the NVD hosts the Layer 2 virtual switch associated with the Layer 2 compute instance.
  3. 4
    The method of any of claims 1-3, wherein the information, the NVD, the Layer 2 virtual network interface, and the Layer 2 virtual switch are first information, a first NVD, a first Layer 2 virtual network interface, and a first Layer 2 virtual switch, respectively, and wherein the method further comprises:generating, based on the input of the customer, second information, the second information comprising the same or different one or more criteria and identifying the same or a different destination;determining that the second information is to be sent to a second NVD of the physical network, wherein the second NVD hosts a second Layer 2 virtual network interface of the plurality of Layer 2 virtual network interfaces and a second Layer 2 virtual switch of a plurality of Layer 2 virtual switches, and wherein the second Layer 2 virtual network interface and the second Layer 2 virtual switch are associated with a second Layer 2 compute instance of the plurality of Layer 2 compute instances;and sending the second information to the second NVD.
  4. 5
    The method of any of claims 1-4, further comprising:determining a customer-specified configuration of the Layer 2 virtual network;and determining a mapping between the customer-specified configuration and a topology of the Layer 2 virtual network, wherein the information is generated further based on the mapping.
  5. 12
    A network virtualization device comprising:one or more processors;and one or more computer-readable storage media storing instructions that, upon execution by the one or more processors, configure the network virtualization device to: host a Layer 2 virtual network interface and a Layer 2 virtual switch that belongs to a Layer 2 virtual network of a customer, wherein: the Layer 2 virtual network interface and the Layer 2 virtual switch are associated with a Layer 2 compute instance that belongs to the Layer 2 virtual network, the Layer 2 compute instance is hosted on a host machine of a physical network that comprises the network virtualization device, the host machine and the network virtualization device being communicatively coupled, and the Layer 2 virtual network is hosted on the physical network and comprises a plurality of Layer 2 compute instances, a plurality of Layer 2 virtual network interfaces, and a plurality of Layer 2 virtual switches;store information indicating one or more criteria associated with copying frames and a destination to receive frame copies;receive a frame, wherein the frame is destined to or originating from the Layer 2 compute instance;115 determine, based on header information of the frame, that the one or more criteria are satisfied;generate a copy of the frame;and send the copy to the destination.
  6. 15
    The network virtualization device of any claims 13-14, wherein the input of the customer indicates that egress frames received on a first port of the Layer 2 compute instance are to be copied and sent on a second port, wherein the execution of the instructions further configure the network virtualization device to:determine a source media access control (MAC) of the frame, wherein the source MAC address is included in the information and is associated with the first port based on a topology of the Layer 2 virtual network;and116 include, in the copy, a destination MAC address, wherein the destination MAC address is included in the information and is associated with the second port based on the topology.
  7. 16
    The network virtualization device of any claims 13-15, wherein the input of the customer indicates that frames received on a first port of the Layer 2 compute instance are to be copied and sent on a second port using an encapsulation protocol, wherein the execution of the instructions further configure the network virtualization device to:determine a media access control (MAC) of the frame, wherein the MAC address is a source MAC address or a first destination MAC address, is included in the information, and is associated with the first port based on a topology of the Layer 2 virtual network;and include, in the copy, a second destination MAC address, wherein the second destination MAC address is included in the information and is associated with the second port based on the topology;and encapsulate the copy based on the encapsulation protocol.
  8. 17
    A system comprising:one or more processors;and one or more computer-readable storage media storing instructions that, upon execution by the one or more processors, configure the system to: generate, based on input of a customer, information indicating one or more criteria associated with copying frames sent in a Layer 2 virtual network and a destination to receive frame copies, wherein the Layer 2 virtual network is hosted on a physical network and comprises a plurality of Layer 2 compute instances, a plurality of Layer 2 virtual network interfaces, and a plurality of Layer 2 virtual switches;determine that the information is to be sent to a network virtualization device (NVD) of the physical network, wherein: the NVD hosts a Layer 2 virtual network interface of the plurality of Layer 2 virtual network interfaces and a Layer 2 virtual switch of the plurality of Layer 2 virtual switches,117 the Layer 2 virtual network interface and the Layer 2 virtual switch are associated with a Layer 2 compute instance of the plurality of Layer 2 compute instances, and the Layer 2 compute instance is hosted on a host machine of the physical network, the host machine and the NVD being communicatively coupled;and send the information to the NVD.
  9. 19
    The system of any claims 17-18, wherein the execution of the instructions further configure the system to:determine a customer-specified configuration of the Layer 2 virtual network;and determine a mapping between the customer-specified configuration and a topology of the Layer 2 virtual network, wherein the information is generated further based on the mapping.