Deployed NSX Management Proxy Supervisor Service and the deployment was successful. However, the communications to ports 10082 and 10081 are down.
This issue causes the Antrea-NSX integration to fail. Affected Versions:
VMware Avi Load Balancer
VMware NSX
VMware NSX-T Data Center
VMware vCenter Server 8.0
VMware Container Networking with Antrea
nsx-management-proxy
Pod and the K8s LB Service proxy-loadbalancer
being realized under different Tier-1 gateways. Therefore, the Avi SE cannot establish connection with the nsx-management-proxy
Pod. Avi SE is attached to a segment under the Tier-1. Therefore, Avi SE cannot use the Tier-1 uplink IP for its traffic, instead, its using the segment subnet. There is also route advertisement rule for Tier-1 to deny advertising the Avi SE segment to other Tier-1s.
Avi SE(under nsx-management-proxy Tier-1) can send a TCP SYN packet to the nsx-management-proxy
Pod on another Tier-1(Supervisor Control Plane VM's Tier-1), but the response TCP SYN+ACK is dropped at the Supervisor Control Plane VM's Tier-1, because Supervisor Control Plane VM's Tier-1 doesn't know how to send the packet back to Avi SE (which is under nsx-management-proxy Tier-1).
Workaround:
nsx-management-proxy
Tier-1 for the Avi SE egress traffic.nsx-management-proxy
Tier-1.
nsx-management-proxy
in the listing -> expand the Tier-1 gateway configuration -> Additional Settings -> Router Links