VPN fails to connect over internet interface in a Multi-Edge SDDC
book
Article ID: 320936
calendar_today
Updated On:
Products
VMware Cloud on AWS
Issue/Introduction
This article provides information when creating a route-based VPN in a Multi-Edge SDDC, traffic from all segments not in a prefix list goes through the default Edge to the remote end. The traffic from other segments are routed through a scaled-out Edge to the VTGW and not included in the forwarding table.
Symptoms: In a Multi-Edge Software-Defined Data Center (SDDC), you experience this symptom:
Traffic from sources that are defined in a prefix list and associated to a Traffic Group are unable to reach route based VPN destinations.
Note: DX- private VIF will not work with Multi-Edge environments.
Cause
This issue occurs as routes over the VMware Transit Gateway (VTGW) takes precedence over VPN routes independent of prefix granularity.
Resolution
This is a known issue affecting VMware Cloud on AWS SDDC version 1.12 and later versions.