Inbound North-South traffic throughput degradation on NSX-T Edge
search cancel

Inbound North-South traffic throughput degradation on NSX-T Edge

book

Article ID: 443140

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention VMware NSX

Issue/Introduction

  • Inbound network speeds (download) drop to ~1 Mbps while internal East-West overlay speeds perform at 16 Gbps.
  • Application disconnects for servers (e.g., SQL, ERP) residing on NSX segments.
  • Edge Node metrics show minimal Data Path CPU usage (<1%) and connection counts (####/2,000,000).
  • No drops or errors observed in standard Edge health check logs.

Environment

  • VMware NSX (all versions)
  • VMware vDefend
  • VMware Cloud Foundation (VCF)

Resolution

Use the following steps to isolate performance degradation in the North-South path:

  1. Verify Stateful Service Resource Pool: Log in to the Edge CLI and run 'edge-appctl -t /var/run/vmware/edge/dpd.ctl mempool/show'. Confirm the 'available_entries' for pfstatepl3 (Stateful Service Pool) is above 0.
  2. Internal Overlay Baseline: Deploy two UPSA appliances on the same overlay segment. See this KB for UPSA deployment instructions. Run iperf3 to verify East-West throughput. Then test with the UPSA appliances on separate segments and separate ESXi hosts. If speeds are as expected according to benchmarks, the virtual overlay and TEP health are confirmed.
  3. Physical Path Isolation: Provision an external physical VLAN just north of the Edge/T0. Place one UPSA appliance on this external VLAN and run iperf3 to an internal segment.
    • If speeds drop significantly, the bottleneck is residing at the Edge or the physical switch infrastructure.
  4. Exclusion List: Ensure all Edge Node vNICs are added to the Distributed Firewall (DFW) Exclusion List to bypass unnecessary host-level inspection.