HCX UI showing error: "attempting to reestablish connect to VM without success....The HCX service is disconnected"
HCX 4.10.x
HCX activation URL connect.hcx.vmware.com is either unreachable, or is being intercepted and re-signed by a 3rd party CA.
Either:
1. Stop intercepting the SSL traffic for HCX or
2. Upgrade HCX to version 4.11
In the 'applianceSummary.txt' file of an HCX log bundle, you can see the latest status for HCX activation URL communication:
"linkLastCommunicated": "Mon Mar 10 12:31:24 UTC 2025",
"linkNextCommunicationDue": "Mon Mar 17 12:31:24 UTC 2025",
"communicationStatus": "Critical (38 days ago)",
If you examine the certificate for the HCX activation URL, you can see that a 3rd party CA has signed it, which indicates SSL interception is occurring.
To obtain the certificate, either use a browser to point to the activation URL, or use Openssl to obtain the cert: openssl s_client -showcerts -connect connect.hcx.vmware.com:443 </dev/null 2>/dev/null|openssl x509 -outform PEM