Inbound North-South traffic throughput degradation on NSX-T Edge
book
Article ID: 443140
calendar_today
Updated On:
Products
VMware vDefend FirewallVMware vDefend Firewall with Advanced Threat PreventionVMware NSX
Issue/Introduction
Inbound network speeds (download) drop to ~1 Mbps while internal East-West overlay speeds perform at 16 Gbps.
Application disconnects for servers (e.g., SQL, ERP) residing on NSX segments.
Edge Node metrics show minimal Data Path CPU usage (<1%) and connection counts (####/2,000,000).
No drops or errors observed in standard Edge health check logs.
Environment
VMware NSX (all versions)
VMware vDefend
VMware Cloud Foundation (VCF)
Resolution
Use the following steps to isolate performance degradation in the North-South path:
Verify Stateful Service Resource Pool: Log in to the Edge CLI and run 'edge-appctl -t /var/run/vmware/edge/dpd.ctl mempool/show'. Confirm the 'available_entries' for pfstatepl3 (Stateful Service Pool) is above 0.
Internal Overlay Baseline: Deploy two UPSA appliances on the same overlay segment. See this KB for UPSA deployment instructions. Run iperf3 to verify East-West throughput. Then test with the UPSA appliances on separate segments and separate ESXi hosts. If speeds are as expected according to benchmarks, the virtual overlay and TEP health are confirmed.
Physical Path Isolation: Provision an external physical VLAN just north of the Edge/T0. Place one UPSA appliance on this external VLAN and run iperf3 to an internal segment.
If speeds drop significantly, the bottleneck is residing at the Edge or the physical switch infrastructure.
Exclusion List: Ensure all Edge Node vNICs are added to the Distributed Firewall (DFW) Exclusion List to bypass unnecessary host-level inspection.