summarize-dvfilter | grep -A9 <Edge VM hostname>vsipioctl getrules -f <slot 2 name from above command>summarize-dvfilter commandVMware NSX 4.x
Since Edge nodes were originally deployed from OVA and not from the NSX UI, they were not automatically added to the DFW Exclusion List. This causes the host to potentially check DFW rules for all traffic to and from the Edge nodes. This can cause high amount of DFW memory usage, despite a low amount of traffic overall. This can cause the host to drop packets when all allowable allocated DFW memory is utilized.
Add the Edge node VMs to the DFW Exclusion List:
In(182) vmkernel: cpu43:16929810)Net: 2621: Created session 14 successfully.In(182) vmkernel: cpu43:16929810)Net: 3808: Filter tuple 5, 4In(182) vmkernel: cpu43:16929810)Net: 3808: Filter tuple 6, 10.##.##.##In(182) vmkernel: cpu43:16929810)Net: 3808: Filter tuple 8, 10.##.##.##In(182) vmkernel: cpu3:2097296)Net: 2733: Destroy session 14 successfully.
summarize-dvfilter | grep -A9 <Edge VM hostname>/bin/vsipioctl getfilterstat -f <slot 2 name from the above command>
DROP REASON-----------memory: 27521