This KB article outlines known issues and symptoms when VMs with High Availability (HA) technologies are connected NSX segments that use the default IP discovery profile and provides a suitable workaround.
The default IP discovery profile has Trust On First Use (TOFU) enabled.
TOFU will keep the initial IP-MAC-Port binding and will assume that it will never expire.
TOFU is not suited for VM HA use cases, as the cluster IP will be reassigned when a standby VM becomes active.
In addition, VMware tools based IP discovery will check IP configuration inside the VM but does not confirm if the IP is actively being used.
It may discover the cluster IP from a standby VM that is not actively using it. As discovered IP addresses are used for NSX L2 forwarding and security features, using the default profile in such scenarios (VM HA) can result in traffic outage.
This is a configuration issue.
Workaround:
Impact/Risks:
This configuration and behavior are applicable for all version of VMware NSX.
Note:
In case of NFV VM HA, the GARP initiated by the NFV VM HA event clears the old ARP/ND learnt IP Discovery bindings.
Related KBs
Windows Failover Cluster does not work as expected when using NSX segments