We have unicast errors in the vmkernel log between the vSAN and Witness network. But the vSAN environment is working fine.
Below are examples of what is seen in the environment
running the esxcli vsan cluster get command shows on each cluster node shows it to be healthy:
Cluster Information:
Enabled: true
Current Local Time: 2025-10-28T21:08:28Z
Local Node UUID: local_node_id
Local Node Type: NORMAL
Local Node State: MASTER
Local Node Health State: HEALTHY
And vSAN witness tagging appears to be correct:
Interface NetstackInstance Tags
--------- ---------------- ----
vmk0 defaultTcpipStack VSANWitness, Management
vmk1 defaultTcpipStack VSAN
vmk2 defaultTcpipStack blank in esxcfg-info_-a.txt
vmk3 vmotion VMotion
vCenter 8
vSAN 8
ESXi 8
It appears that there may be an issue with the tagging that causes the witness traffic to go to a different route
Place each host in the cluster in maintenance mode, one at a time, and then remove the vSAN witness tag from the vmk port and save and then re-tag the vmk port and save