pktcap-uw --switchport <vm_switchportID> --capture VnicTx,VnicRx --mac <multicast_endpoint_mac> --trace > PktHandleID: ######=, Captured at PktFree point, Drop Reason 'VlanTag Mismatch'. Drop Function 'VSwitch_FwdPolicyCheck'. TSO not enabled, Checksum not offloaded and not verified, SourcePort <VM_Switchport>, VLAN tag <vLAN>, VLAN priority 0, QID 0, headroomlen 336, length 60.root@###########-NE-I8 [ ~ ]# tcpdump -i tapbr1 host 224.0.0.1 or host 224.0.0.2 -ean
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on tapbr1, link-type EN10MB (Ethernet), snapshot length 262144 bytes
18:23:58.136503 ##:##:##:##:##:## > 01:00:5e:00:00:01, ethertype IPv4 (0x0800), length 60: #.#.#.#> 224.0.0.1: igmp query v2nsxdp-cli vswitch mcast_filter vswitch get --mode IGMP --dvs-alias <DVS-ALIAS>VMware HCX 4.11.x
This issue is resolved in VMware HCX 4.11.4, available at Broadcom downloads. Refer VMware HCX 4.11.4 Release Notes
If you are having difficulty finding and downloading software, please review the Download Broadcom products and software KB
Workaround
This resolution involves making 2 changes.
Note:
Upgrading HCX to 4.11.4 resolves the Encryption issue. After the upgrade, step 1 in the resolution above still need to be implemented.