VPN session flaps and traffic through VPN is not working even when session is UP.
search cancel

VPN session flaps and traffic through VPN is not working even when session is UP.

book

Article ID: 397962

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Traffic through VPN session does not work even when session status is UP. Peer device sends delete and tears down the session due to inactivity. When NSX Edge VPN side is configured as Initiator, the session is re-negotiated and cycle repeats.

Environment

VMware NSX

Cause

When NAT rule is configured which is matching the VPN Local endpoint IP configured on the same Logical Router due to which source IP/port is changed, then this issue of datapath not working or session flap is seen.

Resolution

This is not a supported configuration where NAT is performed on VPN Local Endpoint IP on same Logical-Router where VPN session is configured: Add an NSX IPSec VPN Service.

Workaround:

Configure No NAT rule for Local endpoint IP and Peer IP as source and destination respectively. No NAT rule priority should be higher than that already existing NAT rule.