Upgrading ESXi host to 8.x fails to reconnect to vCenter after reboot
search cancel

Upgrading ESXi host to 8.x fails to reconnect to vCenter after reboot

book

Article ID: 427442

calendar_today

Updated On:

Products

VMware vSphere ESXi 8.0

Issue/Introduction

  • ESXi 7.x will continue to function normally without issues
  • Post upgrading ESXi host to ESXi 8.x and a reboot, the issue will appear and host may be disconnected from vcenter
  • Attempts to reconnect the host in vCenter Server fail with the error:
“An error occurred while communicating with the host.”
  • vpxd.log shows reconnection failed with Host Communication error
####-##-##T##:##:##.###z error vpxd[06647] [Originator@6876 sub=Default opID=####-3833-auto-2yi-h5:70000683-ab] [VpxLRO] -- ERROR task-5363518 -- 5284d64b-e3c0-bdc3-c0e5-c6e24b244388(524c4c42-89fc-f97a-8135-28456da5b901) -- host-##### -- vim.HostSystem.reconnect: :vmodl.fault.HostCommunication
  • envoy-hgw logs there is 503 returned from host vpxa 
####-##-##T##:##:##.###z info envoy[2020] [Originator@6876 sub=Default] ####-##-##T##:##:##.###z POST /hgw/host-#####/vpxa HTTP/1.1 503 no_healthy_upstream UH 1838 19 - 393 - - - - - ##.##.##.##:443

 

Environment

vCenter 8.x 
ESXi 8.x/7.x

Cause

vCenter and ESXi 8.x introduce TLS session resumption for communication between vCenter Server and hosts. This functionality alters the TLS handshake process compared to earlier versions, such as ESXi 7.x. Issues may arise if external firewalls or security devices are configured to block the TLS session resumption traffic between vCenter and the ESXi hosts

Resolution

Ensure that firewall rules allow unfiltered bidirectional communication over TCP port 443 between vCenter Server and the ESXi host. Please check ports Port requirements for VMware vSphere ESXi 

Additional Information

VMware Ports and Protocols