When a VPN on a T1 is on the same edge node as the active T0 (A/S) Edge, ping works fine from VM Source to remote Destination, but as soon as the T1 is failed over to a different edge residing on a different ESXi host, the ping times out. When the two edge nodes are on the same host, ping works fine.
When T1 VPN is moved to the edge residing on a different ESXi host, the ESP packet goes over the GENEVE tunnel to reach the T0 edge/ESXi host. The recalculation of offloaded checksum in the ESP-IP header is skipped due to GENEVE encapsulation, thereby resulting in packet drop.
Issue is resolved in NSX-T 3.1.3.7 and above.
VPN communication times out