发明名称 Media access control address translation in virtualized environments
摘要 A method and a network device are provided to transmit network packets through a network security device. The method, performed by the network device, receives a request to send a network packet from a first computing device to a second computing device over a network that includes the network device and the network security device. The network packet includes a first network interface identifier for identifying the first computing device and a second network interface identifier for identifying the second computing device. The method identifies third and fourth network interface identifiers that cause the network packet to be transmitted through the network security device. The method transmits the network packet over the network through the network security device using the third and fourth network interface identifiers. The method transmits the network packet to the second computing device using the first and second network interface identifiers.
申请公布号 US9413719(B2) 申请公布日期 2016.08.09
申请号 US201514980110 申请日期 2015.12.28
申请人 Juniper Networks, Inc. 发明人 Litvin Moshe
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Shumaker & Sieffert, P.A. 代理人 Shumaker & Sieffert, P.A.
主权项 1. A method for transmitting network packets through a network security device, the method comprising: receiving, by a first virtual firewall (VF) of a first network device, a network packet from a first virtual machine (VM) hosted by the first network device to be sent over a network to a second VM hosted by a second network device, wherein the network comprises the network security device, a first network switch on a first side of the network security device, and a second network switch on a second side of the network security device, and wherein the network packet comprises a first medium access control (MAC) address identifying the first VM and a second MAC address identifying the second VM; translating, by the first VF, the first MAC address of the network packet to a third MAC address for the first VM hosted by the first network device, wherein the third MAC address belongs to a first network interface connected to the first network switch on the first side of the network security device; translating, by the first VF, the second MAC address of the network packet to a fourth MAC address for the second VM hosted by the second network device, wherein the fourth MAC address belongs to a second network interface connected to the second network switch on the second side of the network security device; and transmitting the network packet from the first VF of the first network device over the network through the first network switch, the network security device, and the second network switch to a second VF of the second network device hosting the second VM based on the third MAC address and the fourth MAC address.
地址 Sunnyvale CA US