Traceflow Drop Reason: SPOOFGUARD
search cancel

Traceflow Drop Reason: SPOOFGUARD

book

Article ID: 443567

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Some workload traffic of VM where the source MAC address differs from the MAC address of vNIC may experience connectivity issues.

This scenario usually occurs when users run special workloads inside the VM, such as:

  • Containers are running inside the VM, and their internal MAC addresses may need to be reachable from the outside.
  • Users craft custom packets using tools like Python Scapy, the MAC address of the egress packet is tweaked.

Environment

VCF 9.0 or higher

Cause

There is due to spoof guard configuration taking effect in the segment.

Resolution

  • Users need to determine whether such traffic (with a MAC address different from the vNIC, or custom packets where egress header is tweaked ) is expected.

  • Leveraging Traceflow to craft the same packet from the VM port can help determine whether the packet is dropped by the SpoofGuard mechanism.
    At Traceflow, based on the observation results, users can clearly understand that the packet is being dropped by SpoofGuard. It will also show where SpoofGuard is taking effect. Users can then check the corresponding SpoofGuard profile to see if "Port Bindings" is enabled.

Additional Information

Create an NSX Spoof Guard Segment Profile