This issue is caused by the vSphere Distributed Switch (VDS) port security policy or Reverse Path Forwarding (RPF) checks on the ESXi host. When L2 bridging is active on a VDS portgroup, the Edge VM forwards traffic for multiple overlay MAC addresses.
If ReversePathFwdCheckPromisc is not enabled, the host may drop this egress traffic or cause MAC learning inconsistencies, leading to packets being looped or dropped by the security layer.
To ensure stable L2 bridging when the Edge VM is connected to a VDS portgroup, perform the following steps on every ESXi host that may host the Edge Transport Nodes:
esxcli system settings advanced set -o /Net/ReversePathFwdCheckPromisc -i 1esxcli system settings advanced list -o /Net/ReversePathFwdCheckPromiscThe preferred configuration for L2 bridging is Option 3: Edge VM is connected to an NSX segment, which leverages native MAC Learning and does not require Promiscuous Mode.
Reference Documentation:
For further assistance, please see Contact Broadcom Support. Scroll to the bottom of the page and click on your respective region.