VMware NSX
If the authentication (TCP 443) and Blast protocol session's (TCP 8443) TCP flows are not landed on the same backend pool member, then the reported issue is observed.
Note: NSX Native Load Balancers do not support cross-VIP TCP session persistence.
If your deployment requires session continuity between Authentication and the Blast protocol, you must use a single L4 TCP 443 Virtual Server for both services. This prevents the session from breaking when transitioning from authentication to the data stream.