NSX BFD Session Remains Down When TEP Endpoints Are in the Same Network
search cancel

NSX BFD Session Remains Down When TEP Endpoints Are in the Same Network

book

Article ID: 428238

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

In a VMware NSX environment, the BFD (Bidirectional Forwarding Detection) session between an NSX Edge node and transport node host does not establish and remains in a Down state

You may observe:

  • BFD status continuously shows Down

  • Repeated BFD INIT packets

  • No tunnel establishment

  • TEP connectivity appears reachable at the host uplink level

  • Edge VM does not receive BFD packets

  • No apparent physical network drop

  • Both are connected to a standard port group for tep network

 

Packet capture analysis shows:

  • Host sends BFD INIT packets (UDP source port 3784) toward Edge

  • Traffic successfully reaches the destination host uplink

  • Packets do not reach the Edge VM interface

  • Edge sends return packets host (source)

  • Return packets reach the destination host

  • BFD session never establishes and continuously retries INIT

 

Environment

VMware NSX

Cause

The issue occurs when the communicating TEP endpoints reside in the same IP network/subnet.

In this scenario, packets are received at the destination host uplink but are dropped at the NSX Distributed Router (VDR) because MAC learning does not occur correctly for same-network routing behavior.

As a result, packets never reach the Edge VM virtual NIC

Resolution

Move the affected workloads to a different non-overlapping IP range so the endpoints are no longer in the same network.

OR

If both endpoints must remain in the same VLAN:

Connect the Edge TEP interface to a VLAN segment

Additional Information

No further port-level connectivity testing between the hosts is required

The physical network is forwarding packets correctly

The issue is related to IP addressing and NSX logical routing behavior

Overlay tunnels cannot form while BFD remains down, which may impact:

  • Tier-0/Tier-1 routing

  • Edge connectivity

  • Overlay transport reliability