When pairing sites or during standard replication operations in VMware Cloud Director Availability (VCDA) 4.x, you observe the following symptoms:
"Generic error during the SSL Handshake".vmnic1 and vmnic7), the Tunnel appliance loses all connectivity when one physical uplink is brought down, even if the Replicator appliance on the same host fails over correctly.This issue is caused by a physical network layer misconfiguration where the required replication VLANs are not consistently defined or allowed across all physical trunk ports (uplinks) connected to the ESXi host.
Specifically, if the replication VLAN is "pruned" or restricted on one physical uplink but not the other, the VCDA Tunnel appliance may become "pinned" to a specific path. When that path fails or the vDS attempts to balance traffic to the restricted uplink, the MAC learning fails, and the SSL handshake times out because the packets cannot reach the destination.
To resolve this issue, reconfigure the physical switch ports to ensure that all replication-related VLANs are fully allowed on all uplinks serving the ESXi host.
After resolving the networking issues, retry the site pairing task from VCDA:
For an environment with two Cloud Director sites, Pair or Re-pair the site.
For an environment with On-Premises sites, Re-pair the remote site.