When utilizing VMware HCX with Palo Alto firewalls in the network path, HCX Network Extension (NE) tunnels may unexpectedly go down despite no configuration changes being made to the firewall or network. The following symptoms may be observed:
The issue is caused by a known behavior in Palo Alto firewalls regarding session handling for UDP traffic (including IPsec ESP packets, which HCX uses for its tunnels).
Palo Alto firewalls create and use session records while processing traffic. Sessions can exist in various states, including "Discard" state. When a session is in "Discard" state, any packet that hits that session is dropped by the firewall. In some scenarios, sessions may become stuck in "Discard" state or not properly transition states when expected.
Two common scenarios that affect HCX tunnels:
This behavior can occur even when there have been no configuration changes to the firewall or network. This is seen especially in environments where there is double encryption causing MTU issues.
Verify that your HCX environment has proper MTU configuration to ensure stability. Follow the guidance in Configuring MTU for VMware HCX Components and Infrastructure to ensure proper MTU settings for your environment.
If you are using encryption for a VPN over the Palo Alto or upstream router please consider disabling Encryption on your network profile if your network is already secure.
> show session all filter source [HCX NE IP 1] destination [HCX NE IP 2] state discard
> show session all filter source [HCX NE IP 2] destination [HCX NE IP 1] state discard
> show session all filter state discard
> show session all filter source [HCX NE IP 1] destination [HCX NE IP 2]
> show session all filter source [HCX NE IP 2] destination [HCX NE IP 1]
Option A: Clear individual sessions
> clear session id [Session Id]
Option B: Clear all sessions matching specific criteria (more efficient for multiple sessions)
> clear session all filter source [HCX NE IP 1] destination [HCX NE IP 2]
> clear session all filter source [HCX NE IP 2] destination [HCX NE IP 1]
> clear session all filter state discard
To prevent this issue from recurring:
If the error persists after following these steps, contact Palo Alto support for further assistance.
Related Article: