NSX Traceflow fails with reason "Dropped by VLAN"
search cancel

NSX Traceflow fails with reason "Dropped by VLAN"

book

Article ID: 445450

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Users can encounter the drop reason "VLAN" when using VLAN Traceflow for traffic across different VLANs.
  • The drop reason "VLAN" means the Traceflow packet is dropped by the port because the VLAN of the packet does not match the VLAN of the port. It usually indicates the Traceflow packet is not processed by the router.

    Traceflow UI output:


Environment

VMware NSX

Cause

This is usually caused by users trying a cross-VLAN Traceflow without setting the destination MAC address to the MAC address of the gateway/router.

Resolution

  • Once this drop reason is encountered, users need to check whether the source and destination are in different VLAN segments first.
  • If they are in different VLAN segments, users need to properly update the destination MAC address of the Traceflow to the gateway/router address for these two VLAN segments,This is because the cross-VLAN traffic has to be routed by the gateway/router first.
  • After users populate the proper gateway/router MAC address as the destination MAC of the traceflow, then try the traceflow again.
  • If the gateway/router routes the Traceflow packet correctly, users will eventually see the end-to-end traffic path from the Traceflow UI or API.




Additional Information

Please refer to the KB for additional information regarding the destination MAC: https://knowledge.broadcom.com/external/article/422412/users-need-to-notice-the-destination-mac.html