Palo Alto Firewall VM Sees Standby Edge Node MAC Address in ARP Table Causing It To Be Unreachable From External Connections
search cancel

Palo Alto Firewall VM Sees Standby Edge Node MAC Address in ARP Table Causing It To Be Unreachable From External Connections

book

Article ID: 394042

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Symptoms: 

  • Two node Edge cluster and both Edge nodes are on the same ESXi Host.
  • Edge TEPs and ESXi TEPs are in the same IP subnet.
  • Affected VMs and Edge nodes are using the same N-VDS/VDS. 

In this scenario where there is a single VDS in use by the unreachable VMs and the Edge node VMs, the unreachable VMs will have ARP entries for the Standby Edge node and no ARP entries for the Active Edge node. 

Environment

VMware NSX-T Data Center

VMware NSX 4.x

Cause

The root cause of this behavior is not currently known. 

Separating Edge nodes across ESXi hosts will protect against a host failure scenario.

Resolution

Migrate one Edge node to a different ESXi Host than the active node. 

Create an affinity rule (VM-Host) to keep Edge nodes on separate ESXi Hosts. 

Additional Information

Similar behavior has been seen in older ESXi/NSX-T versions. 

If this issue is seen, please collect and provide the following data through a Support Request: 

  • MAC/ARP table from physical switch 
  • Logs from physical switch
  • MAC/ARP tables from both Edge nodes
  • Logs for both Edge nodes