HCX - Error while performing Network Extension "Remote endpoint invalid"
search cancel

HCX - Error while performing Network Extension "Remote endpoint invalid"

book

Article ID: 321636

calendar_today

Updated On:

Products

VMware HCX VMware Cloud on AWS

Issue/Introduction

Identify a failure condition, that will disrupt Network Extension and Migration services due to unhealthy Site Pair connection. Provide a procedure for the restoration.

During initiation of a Network Extension for a given segment, the "NEXT" option will remain grayed out and below error notification will be seen on the NE wizard:
Go to Network Extension >> Extend Networks >> SELECT a Source Network >> NEXT



Environment

VMware HCX

Cause

Once you load Network Extension or Mobility Migrations wizard, the Source/Connector system try to fetch resources(destination container/networks etc.) from Cloud/Peer system.
During this workflow, HCX Connector system performs real time login to HCX Cloud manager based on the existing Site Pair connectivity.
If the login operation fails between site paired manager, it will cause the above error condition.

Resolution

None

Workaround:
As highlighted in the cause section, this issue generally happens when Site Pair connection is not healthy, which impacts the overall connectivity between source and target HCX system.

Note: During validation of the Site Pair, you may notice the Site Pair connection showing green OR healthy on the UI, but that is an UI behavior.

To verify, whether Site Pair is really Up & healthy, the recommendation is to follow below steps:

Step 1: Go to Site Pairing wizard and click on "Edit Connection" as below:

Site Pairing >> EDIT CONNECTION >> Enter Username/Password >> Click on EDIT


Step 2: If Site Pair connection fails to establish post editing the connection, check below:

  • Verify IP/FQDN for the Cloud HCX Manager is valid and DNS server configured in the HCX Connector Manager is able to resolve the FQDN.
  • Verify SSO user group/role associated to the Cloud vCenter/HCX and ensure that, the group/role exists on the vCenter. 
    • Try to access HCX Cloud Manager using those SSO credentials for further validations.
    • If SSO group/role doesn't exist or may have been removed mistakenly in the past from either vCenter(Administration >> Single Sign On >> Users and Groups) OR HCX Cloud Manager 9443 UI(Configuration >> Role Mapping), please re-add the roles and ensure HCX Cloud Manager is accessible now using SSO credentials.

Step 3: Post remediation using Step 2, please follow Step 1 to re-register site pairing between Connector & Cloud Manager.


Additional Information

Refer KB-321629  for generic site pair diagnostics & validations.
Refer KB-321598  for DNS resolution & validations.

Impact/Risks:

  • All new Migration & Network Extension workflow will remain affected.
  • There is NO impact to existing Network Extensions over datapath.


"Remote endpoint invalid" was noted when getting the Network Extension Information. Reauthenticating with the cloud NSX fixed the issue.