In a VCF 9.1 environment using HCX Network Extension (NE), you may observe the following:
VCF Operations HCX 9.1
Non-default or Global SpoofGuard profiles enforce strict address bindings to prevent spoofing. When a VM is migrated via HCX 9.1, its traffic is proxied through the HCX appliance. If a strict Global SpoofGuard policy is in place, the NSX datapath on the host does not recognize the returning traffic (such as the ARP reply from a non-migrated VM) as being authorized for that specific logical port. Consequently, the NSX SpoofGuard filter drops the packet at the host level before it can be delivered to the VM.
If this is a test segment and not currently in production, you can try the following workaround to verify and restore connectivity:
If your environment requires a specific Global SpoofGuard policy or if you are unable to change the profile due to organizational security constraints:
A similar connectivity issue can occur if MAC Learning is incorrectly configured or disabled on the NSX segment.
For issues where VMs are unable to communicate over newly created HCX Layer 2 extended networks specifically due to MAC Discovery profile settings, please refer to:
VM connectivity issues observed over a newly created HCX Layer 2 extended network