NSX-T EVPN - Traffic from VNF to DCGW is dropped every 10 minutes as the Type-2 route is withdrawn from Edge
search cancel

NSX-T EVPN - Traffic from VNF to DCGW is dropped every 10 minutes as the Type-2 route is withdrawn from Edge

book

Article ID: 322642

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Traffic from VNF (Virtual Network Function) to DCGW (Data Center Gateway) is dropped every 10 minutes for one second or less.
  • The default IP Discovery profile is set on the segments with a default timeout of 10 minutes.
  • /var/log/syslog on edge shows the ARP being removed and created every 10 minutes.

2023-03-21T00:35:45.635Z sesbg-nf272bm03 NSX 8598 SWITCHING [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="neigh" tname="dp-###" level="INFO"] dynamic arp entry(1107afc9-####-####-####-##########aa, 192.168.10.19) is removed
2023-03-21T00:35:46.040Z sesbg-nf272bm03 NSX 8598 SWITCHING [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="neigh" tname="dp-###" level="INFO"] dynamic arp entry(1107afc9-####-####-####-##########aa, 192.168.10.19) is created
2023-03-21T00:45:46.812Z sesbg-nf272bm03 NSX 8598 SWITCHING [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="neigh" tname="dp-###" level="INFO"] dynamic arp entry(1107afc9-####-####-####-##########aa, 192.168.10.19) is removed
2023-03-21T00:45:47.255Z sesbg-nf272bm03 NSX 8598 SWITCHING [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="neigh" tname="dp-###" level="INFO"] dynamic arp entry(1107afc9-####-####-####-##########aa, 192.168.10.19) is created

Environment

VMware NSX-T Data Center 3.x
VMware NSX

Cause

Edge DP probes ARP every 10 minutes. IP Discovery profile is also set to 10 minutes. So IP-MAC is expired at the 10th minute and is learned immediately. However, this can still create fluctuation in the traffic.

Resolution

This issue is resolved in VMware NSX 3.2.4
This issue is resolved in VMware NSX 4.1.1
This issue is resolved in VMware NSX 4.2.0


Workaround:

Create the new IP Discovery profile with a timeout value of 20 minutes. Then change the segment’s default IP Discovery to the new profile. Alternatively set the VNF ARP timer to less than 10 minutes.