To assist in troubleshooting routing misconfiguration and to restore VPN connectivity.
Symptoms:
Due to routing misconfiguration, VPN session comes up, IPSec tunnels come up and DPD gets triggered due to the routing loop and session goes down. This process repeats until the routing configuration is fixed.
VMware NSX-T Data Center
VMware NSX-T Data Center 2.5.x
VMware NSX-T Data Center 3.x
Peer's IPSec Local IP is distributed over VTI of IPSec tunnel, causing a routing loop.
The steps to correct the routing configuration depend on the environment. There are 4 scenarios:
Note: *For tier1, "IPSec Local IP" will be defined as "IPSec Local Endpoint".
Related documentation: