Measurement based routing through multiple public clouds
First Claim
1. A method for establishing a virtual network for an entity over a plurality of public cloud datacenters of a plurality of public cloud providers, the method comprising:
- deploying first and second sets of forwarding elements in first and second multi-tenant public cloud datacenters operated by first and second public cloud providers;
configuring a set of measurement agents deployed in the first and second public cloud datacenters to obtain measurements regarding connections between forwarding elements in the first and second sets;
based on the obtained measurements, defining virtual-network routes through the first and second set forwarding elements;
distributing said routes to the first and second sets of forwarding elements to configure these elements to implement the virtual network;
wherein a set of controllers aggregates said measurements, and based on the aggregated measurements, defines the virtual-network routes; and
wherein the virtual-network routes are overlay routes established by encapsulating data messages traversing these routes with encapsulation headers that store network addresses for ingress and egress forwarding elements for entering and exiting the virtual network and network addresses of next hop forwarding elements for identifying next hop destinations for traversing the virtual network.
3 Assignments
0 Petitions
Accused Products
Abstract
Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity'"'"'s data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.
-
Citations
15 Claims
-
1. A method for establishing a virtual network for an entity over a plurality of public cloud datacenters of a plurality of public cloud providers, the method comprising:
-
deploying first and second sets of forwarding elements in first and second multi-tenant public cloud datacenters operated by first and second public cloud providers; configuring a set of measurement agents deployed in the first and second public cloud datacenters to obtain measurements regarding connections between forwarding elements in the first and second sets; based on the obtained measurements, defining virtual-network routes through the first and second set forwarding elements; distributing said routes to the first and second sets of forwarding elements to configure these elements to implement the virtual network; wherein a set of controllers aggregates said measurements, and based on the aggregated measurements, defines the virtual-network routes; and wherein the virtual-network routes are overlay routes established by encapsulating data messages traversing these routes with encapsulation headers that store network addresses for ingress and egress forwarding elements for entering and exiting the virtual network and network addresses of next hop forwarding elements for identifying next hop destinations for traversing the virtual network. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A system for establishing a virtual network for an entity over a plurality of public cloud datacenters in a plurality of regions, the system comprising:
-
a first set of forwarding elements in a first multi-tenant public cloud datacenter in a first region; a second set of forwarding elements in a second multi-tenant public cloud datacenter in a second region different than the first region; a set of measurement agents deployed in the public clouds to obtain measurements regarding connections between forwarding elements in the first and second sets; a set of controllers to aggregate said measurements and to define virtual-network routes through the first and second set forwarding elements, said routes distributed to the first and second sets of forwarding elements to configure these elements to implement the virtual network; and wherein the virtual-network routes are overlay routes established by encapsulating data messages traversing these routes with encapsulation headers that store network addresses for ingress and egress forwarding elements for entering and exiting the virtual network and network addresses of next hop forwarding elements for identifying next hop destinations for traversing the virtual network. - View Dependent Claims (12, 13, 14, 15)
-
Specification