Symptom:
The VM is configured on a Secondary VLAN (e.g., ##91).
The VDS is configured with a Primary VLAN (e.g., ##90).
Ingress traffic from the physical switch arrives tagged with the Secondary VLAN ID (##91).
"pktcap-uw --trace --mac [MAC_Address_Of_Target_VM]" output example:
VMware vCenter Server.
VMware vSphere ESXi.
This issue occurs when the upstream physical switch port connected to the ESXi host is misconfigured to actively translate Private VLAN tags (e.g., operating as a secondary PVLAN trunk) rather than acting as a standard 802.1Q trunk.
In a vSphere Distributed Switch (VDS) PVLAN implementation, the VDS handles the translation between Secondary and Primary VLANs locally. The ESXi host's internal MAC address learning table identifies the default gateway as a Promiscuous device. Therefore, the VDS explicitly expects North-South return traffic from that gateway to arrive at the physical uplink tagged with the Primary VLAN ID.
To resolve this issue, the physical network ports connected to the ESXi host uplinks must be configured to pass the VLAN tags completely unmodified. Work with your network administrator to apply the following changes: