`Dropped by VLAN`VMware NSX
This issue is caused by a known architectural limitation. The NSX Edge does not currently support the processing or re-injection of Traceflow packets that originate from a VLAN-backed segment when they are destined for an Overlay-backed segment.
This is expected behavior and does not indicate a failure in the actual network data plane.
Subscribe to this knowledge article for updates regarding future support for this Traceflow path.
Workaround
To verify the logical pipeline and firewall rule enforcement between these segments, perform the following:
Alternatively, use standard packet capture tools (e.g., `pktcap-uw` on the ESXi hosts or the NSX Packet Capture tool) to verify the transit of actual production traffic.
NSX 4.1 Administration Guide: Perform a Traceflow.