After a scheduled firewall maintenance window, the existing VMware HCX Interconnect (HCX-IX) tunnels to Azure VMware Solution (AVS) remain in a "Down" state within the HCX Manager UI.
VMware HCX
This issue is caused by stale stateful sessions on the transit firewall. During the firewall maintenance or interruption, the state table entries for the specific streams used by the HCX-IX and Network Extension (NE) appliances became hung or desynchronized. Because the firewall retains these stale session entries, it drops or mishandles the continuous probe packets sent by the mesh appliances, preventing the persistent tunnel from re-establishing automatically.
To resolve this issue and restore the existing tunnels without canceling active Bulk Migrations, you must clear the stale sessions from your firewall:
The mesh appliances will automatically send new probe packets, establish a fresh stateful session on the firewall, and bring the tunnels back up. Any Bulk Migrations that were in progress will resume an active synchronization state.