The following conditions will confirm the issue:
- NSX-T running version 3.1.2.0 or earlier
- Traffic for MON enabled VMs being routed beyond the NSX Tier-1 into the Tier-0
- Error messages "Failed to add neigh route" appear constantly in NSX Edge /var/log/syslog
- Tier-1 logical router forwarding table is missing the Gateway IP for the MON /32 host routes:
localhost> get logical-router 74fc7ec3-64b4-4308-9fca-33b1c381a24a forwarding
Wed Oct 13 2021 UTC 19:19:45.071
Logical Router
UUID VRF LR-ID Name Type
74fc7ec3-64b4-4308-9fca-33b1c381a24a 3 2 DR-cloud-tier1-router-1 DISTRIBUTED_ROUTER_TIER1
IPv4 Forwarding Table
IP Prefix Gateway IP Type UUID Gateway MAC
172.16.128.46/32 <missing> route 539c2727-fb8b-4a3e-a69a-369f2901fbff 00:50:56:a2:ee:bb
Learning packets:
{
"arp_cache_learning_req_enqueue_failures": 0,
"arp_cache_learning_req_oom_failures": 0,
"arp_cache_learning_req_processed": 0,
"arp_learning_req_enqueue_failures": 0,
"arp_learning_req_oom_failures": 0,
"arp_learning_req_processed": 6608,
Note: All routes and identifiers are used for example purposes only. Actual identifiers will be different in your environment.
Impact/Risks:
- This issue ONLY affects traffic for MON enabled VMs that is routed beyond the Tier-1 to the Tier-0.
- Optimized traffic for MON enabled VMs within the same Tier-1 is NOT affected.
- L2 traffic over the HCX L2 Network Extension is NOT affected.
- Sustained high CPU on the NSX Edge may impact other routing functions.