Temporary L2VPN network loss after vmnic failover or vMotion of NSX Edge
search cancel

Temporary L2VPN network loss after vmnic failover or vMotion of NSX Edge

book

Article ID: 325068

calendar_today

Updated On:

Products

VMware

Issue/Introduction

Temporary network loss occurs in the following scenario.

VM1--Edge1(L2 VPN server)--Internet--Edge2(L2 VPN Client)--VM2

L2 VPN tunnel is configured between NSX Edge L2 VPN server and NSX Edge L2 VPN client or Standalone Edge Client.

-Edge2 and VM2 are on different ESXi hosts.
-Physical NIC failover happens on trunk port group to which Edge2 is connected or vMotion of Edge2 appliance occurs.

RARP for the VM1 on the other site will not be sent to the switch port to which the Edge2 newly connects. Therefore, the network switch does not know the new connection of VM1 and wrongly sends packet to the old port. 
Temporary connection loss occurs until the MAC address table on the switch expires, or a new packet arrives from VM1.


Resolution

As VDS or VSS is not responsible to send RARP packets for VMs on the other site, this is the expected behavior. To reduce the impact of network loss, take the following actions:
-Reduce MAC address aging time on the switch.
-Continually send ping from both ends of the L2 VPN tunnel.