The issue happens if the TKG node VMs are placed on NSX-T-backed virtual networks and the CNI configured is Antrea, which creates a double-Geneve encapsulation.
This is a known bug affecting TKG clusters configured with Antrea CNI when the node VMs are placed in NSX-T backed virtual networks.
It is resolved in NSX 3.1.3 or 3.2.1 if Enhanced Datapath is enabled
Workaround:
To workaround the issue, use Calico as the CNI, which uses VXLAN, instead of Antrea.
If Antrea is required, checksum offloading can be disabled using TKG Configuration File variable ANTREA_DISABLE_UDP_TUNNEL_OFFLOAD