Cannot Add Tier-0 VRF Gateway to a Tier-0 Gateway in Active-Active Stateful HA Mode
search cancel

Cannot Add Tier-0 VRF Gateway to a Tier-0 Gateway in Active-Active Stateful HA Mode

book

Article ID: 442835

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

In VMware NSX, an error occurs when trying to attach a Tier-0 VRF gateway to a parent Tier-0 Gateway configured in Active/Active Stateful High Availability (HA) mode. The same error manifests if an operator attempts to alter the HA configuration of an existing Tier-0 Gateway to Active/Active Stateful while VRF gateways are attached.

The following explicit error message is returned within the NSX Manager user interface or API payloads: "VRF is not supported on Active-Active stateful Tier0 /infra/tier-os/<Tier_0_name. (Error code: 503632)"

Environment

VMware NSX

Cause

Tier-0 VRF gateways are architecturally unsupported on parent Tier-0 Gateways operating in Active-Active Stateful High Availability mode due to product design limitations concerning interface groups and stateful traffic punting mechanisms across virtual routing instances.

Resolution

To utilize Tier-0 VRF multi-tenancy configurations, deploy or reconfigure the parent Tier-0 Gateway to use an architecturally supported topology:

  1. Configure the parent Tier-0 Gateway in Active-Active Stateless Mode. VRF instances are fully supported when centralized stateful services are omitted at the Tier-0 tier.

  2. Alternatively, configure the parent Tier-0 Gateway in Active-Standby Mode if localized stateful services (such as NAT, URL Filtering, or Gateway Firewalls) must co-exist with VRF-lite routing isolation.

Note: Reconfiguring the High Availability mode of a production Tier-0 Gateway destroys stateful contexts and resets Edge routing peerings, causing a temporary disruption to North-South data paths. Perform this adjustment only within a designated maintenance window.