When moving to AVS Express Route whether it is for a new deployment or transitioning an existing deployment to Express Route from another setup, such as VPN, users sometimes experience issues with being unable to route the traffic for the HCX site pairing across the express route as expected. This can cause the site pairing to be completely down, sometimes it can cause flapping, and in some circumstances this could show the site pairing up on only one side of the connection.
HCX
AVS ExpressRoute
AVS by Microsoft automatically routes traffic between the onPrem site and AVS using BGP with ECMP (Equal Cost Multi Path). onPrem users sometimes will use a single HCX Manager for multiple site pairs, likely due to restrictions when it comes to vCenter licensing. This is achieved by using separate paths and sometimes separate virtual routing tables onPrem. When this traffic gets to the ExpressRoute BGP connection, it is able to send over the route to AVS, but when the traffic gets to AVS, if there are multiple site pairings, the route in the ExpressRoute will not know which way to send the traffic to the HCX Managers, and this causes the site pairing to inconsistently find the HCX Manager.
To resolve HCX site pairing connectivity issues over ExpressRoute when using multiple site pairs with a single HCX Manager, implement one of the following solutions
For optimal results, we recommend option #1 as it requires minimal configuration changes while effectively solving the routing ambiguity by leveraging ECMP's preference for more specific routes. If licensing allows, option #2 provides the cleanest separation and eliminates routing ambiguity entirely. If licensing allows, option #2 provides the cleanest separation and eliminates routing ambiguity entirely.
After implementing the solution, verify that the issue is resolved by:
If issues persist after implementing these solutions, consider opening a support case with Microsoft.
If you still need help after reaching out to Microsoft please reference this article and provide the below information when opening a support request with Broadcom for this issue