Error: Local endpoint overlaps with tier-0 transit subnet from provider
search cancel

Error: Local endpoint overlaps with tier-0 transit subnet from provider

book

Article ID: 418582

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • You are trying to create a VPN Local Endpoint.
  • The creation fails with a message indicating that the Local Endpoint IP address overlaps with a Tier-0 transit subnet.

    Error: Local endpoint [/infra/tier-1s/###########/ipsec-vpn-services/###########/local-endpoints/###########] overlaps with tier-0 transit subnet from provider [/infra/tier-0s/###########]. (Error code: 501838)

  • Inspecing the existing Tier-0 transit interfaces, no subnet is seen to overlap with the desired Local Endpoint IP address.
  • However, the T0-T1 Transit Subnets property of the Tier-0 router from the error message (under Additional Settings) overlaps with the desired Local Endpoint IP address.

Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.

Environment

VMware NSX

Cause

VPN Local Endpoint can not overlap with T0-T1 Transit Subnets. This range is used for creation of transit subnets between T0 and T1.
See NSX Documentation: Add an NSX Tier-0 Gateway

Resolution

This is a condition that may occur in a VMware NSX environment.

Please use a VPN Local Endpoint IP address that doesn't overlap with the T0-T1 Transit Subnets.