Detecting failure of layer 2 service using broadcast messages
Abstract
Some embodiments provide a method for detecting a failure of a layer 2 (L2) bump-in-the-wire service at a device. In some embodiments, the device sends heartbeat signals to a second device connected to L2 service nodes in order to detect failure of the L2 service (e.g., a failure of all the service nodes). In some embodiments, the heartbeat signals are unidirectional heartbeat signals (e.g., a unidirectional bidirectional-forwarding-detection (BFD) session) sent from each device to the other. The heartbeat signals, in some embodiments, use a broadcast MAC address in order to reach the current active L2 service node in the case of a failover (i.e., an active service node failing and a standby service node becoming the new active service node). The unidirectional heartbeat signals are also used, in some embodiments, to decrease the time between a failover and data messages being forwarded to the new active service node.
Claims
exact text as granted — not AI-modified1 - 19 . (canceled)
20 . A method for performing a service at an edge router comprising first and second interfaces, the method comprising:
configuring the edge router to send, through the first interface, packet flows to a service machine to perform the service and to receive, from the second interface, the serviced packet flows; configuring the edge router to send, from the first interface, a first set of heartbeat data messages to the service machine and to process a second set of heartbeat data messages received from the service machine along the second interface; and configuring the edge router to determine that the service machine has failed based on a period of time associated with receiving heartbeat data messages in the second set of heartbeat data messages.
21 . The method of claim 20 , wherein data messages in the first set of heartbeat data messages traverse a datapath comprising a first switch through which the first set of heartbeat data messages traverse from the first interface to the service machine, and a second switch through which the second set of heartbeat data messages traverse from the service machine to the second interface.
22 . The method of claim 21 , wherein each switch associates a port of the switch with media access control (MAC) addresses used as source addresses for data messages received at the port.
23 . The method of claim 22 , wherein the period between data messages in each of the first and second sets of heartbeat data messages is less than a time period for a timeout of a learned media access control (MAC) address.
24 . The method of claim 20 , wherein the service machine is part of a cluster of service machines that perform the service, and the data messages of the first set of data messages use a broadcast destination media access control (MAC) address in order to reach the service machine that is the active service machine in the cluster to perform the service.
25 . The method of claim 24 , wherein the service machines provides the service for packet flows without changing source and destination media access control (MAC) addresses of the packet flows.
26 . The method of claim 24 , wherein the cluster of service machines determines which service machine in the cluster is the active independent of the heartbeat data messages sent to and from the edge router.
27 . The method of claim 24 , wherein
data messages in the first set of heartbeat data messages traverse a datapath comprising a first switch through which the first set of heartbeat data messages traverse from the first interface to the service machine, and a second switch through which the second set of heartbeat data messages traverse from the service machine to the second interface, the first switch associates a MAC address of the first interface with a first port to which the first interface is connected based on the first data message being received from the first interface, and the second switch associates the MAC address of the first interface with a second port to which the active service machine is connected based on the first data message being received from the active service machine.
28 . The method of claim 20 further comprising dropping data messages that require the service determining that the service machine has failed.
29 . The method of claim 20 , wherein the particular service is one of a firewall operation, a network address translation, and a load balancing operation, and the service machine is a service virtual machine or a service appliance.
30 . A non-transitory machine readable medium storing a program which when executed by at least one processing unit configures an edge router comprising first and second interfaces to provide a service for a plurality of packet flows processed by the edge router, the program comprising sets of instructions for:
configuring the edge router to send, through the first interface, packet flows to a service machine to perform the service and to receive, from the second interface, the serviced packet flows; configuring the edge router to send, from the first interface, a first set of heartbeat data messages to the service machine and to process a second set of heartbeat data messages received from the service machine along the second interface; and configuring the edge router to determine that the service machine has failed based on a period of time associated with receiving heartbeat data messages in the second set of heartbeat data messages.
31 . The non-transitory machine readable medium of claim 30 , wherein data messages in the first set of heartbeat data messages traverse a datapath comprising a first switch through which the first set of heartbeat data messages traverse from the first interface to the service machine, and a second switch through which the second set of heartbeat data messages traverse from the service machine to the second interface.
32 . The non-transitory machine readable medium of claim 31 , wherein each switch associates a port of the switch with media access control (MAC) addresses used as source addresses for data messages received at the port.
33 . The non-transitory machine readable medium of claim 32 , wherein the period between data messages in each of the first and second sets of heartbeat data messages is less than a time period for a timeout of a learned media access control (MAC) address.
34 . The non-transitory machine readable medium of claim 30 , wherein the service machine is part of a cluster of service machines that perform the service, and the data messages of the first set of data messages use a broadcast destination media access control (MAC) address in order to reach the service machine that is the active service machine in the cluster to perform the service.
35 . The non-transitory machine readable medium of claim 34 , wherein the service machines provides the service for packet flows without changing source and destination media access control (MAC) addresses of the packet flows.
36 . The non-transitory machine readable medium of claim 34 , wherein the cluster of service machines determines which service machine in the cluster is the active independent of the heartbeat data messages sent to and from the edge router.
37 . The non-transitory machine readable medium of claim 34 , wherein
data messages in the first set of heartbeat data messages traverse a datapath comprising a first switch through which the first set of heartbeat data messages traverse from the first interface to the service machine, and a second switch through which the second set of heartbeat data messages traverse from the service machine to the second interface, the first switch associates a MAC address of the first interface with a first port to which the first interface is connected based on the first data message being received from the first interface, and the second switch associates the MAC address of the first interface with a second port to which the active service machine is connected based on the first data message being received from the active service machine.
38 . The non-transitory machine readable medium of claim 30 further comprising dropping data messages that require the service determining that the service machine has failed.
39 . The non-transitory machine readable medium of claim 30 , wherein the particular service is one of a firewall operation, a network address translation, and a load balancing operation, and the service machine is a service virtual machine or a service appliance.Join the waitlist — get patent alerts
Track US2024015086A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.