Long-lived traffic from GVMs is not redirected to Partner service VMs.
Symptoms:
- E-W Service insertion enabled.
- Stateful SI firewall policies are configured.
- SI failover policy is "allow"
- The environment uses applications or protocols that maintains long-running sessions (Example: client and server that maintain a long-lived connection, protocols like SCTP etc.)
- The traffic subjected to stateful firewall not redirected to Partner SVMS.
- Dfwpkt.log don’t show rule hit logs.
- There will be an existing flow for the respective source and destination IP in the flow table "vsipioctl getflows -f <slot 12 filter>"
- Intermittent issues on the partner SVMs such as SVM not responding to liveliness packets, SVM interface up/down, SVM reboot etc. that is causing "service Endpoint Down" alerts in the Vmkernal.log
Example logs:
2024-08-21T10:56:48.439Z cpu18:2110632)NetX Proxy: Service Endpoint with MAC: 00:xx:xx:xx:xx:xx is down
2024-08-21T10:56:48.439Z cpu18:2110632)vif id for switch port xxxxx is xxxxxxxx-xxxx-xxx-xxxxxxxxxx
2024-08-21T10:56:48.439Z cpu18:2110632)NetX Proxy: Sent message to LCP for to_Failure