After deploying HCX Manager in Amazon Elastic VMware Service (EVS), the HCX Manager appears to be down or unreachable when attempting to connect from virtual machines located in a different subnet on a separate VPC. While the HCX deployment completes successfully, VMs in other VPCs cannot establish connectivity to the HCX Manager, making it appear as though the service is offline.
Symptoms:
The HCX Manager is running correctly but cannot be reached due to network isolation between VPCs in Amazon EVS. As documented in Getting started with Amazon Elastic VMware Service, Amazon EVS does not support connectivity via an AWS Direct Connect private virtual interface (VIF) or via an AWS Site-to-Site VPN connection that terminates directly into the underlay VPC. Management VMs (jumpbox) and HCX Manager residing in separate VPCs cannot communicate without additional AWS networking configuration using Transit Gateway.
To restore connectivity to the HCX Manager when management VMs are in a different VPC:
Important Note: Transit Gateway is currently the only supported method for enabling communication between VPCs in Amazon EVS. Direct VPC peering or routing without Transit Gateway is not supported. As Amazon EVS is in public preview, this requirement may change when the service reaches general availability (GA).
Alternative deployment option: