nsxcli -c "get logical-switch <VNI> arp-table" The ESXi Geneve/VXLAN netstack maintains only a single default gateway for TEPs, derived from the first acquired subnet. If a TEP IP Pool contains multiple subnets, VTEPs assigned to a secondary subnet experience network unreachability. When such a host is designated as a proxy for Hierarchical Two-Tier (MTEP) replication, it cannot forward ARP broadcast frames to hosts in other subnets. This routing behavior is a design limitation.
Temporary Workaround (Immediate Mitigation) To immediately restore E-W connectivity without rebooting hosts or altering IP allocations, bypass the MTEP proxy host mechanism:
Log in to the NSX Manager UI.
Navigate to Networking > Segments and select the affected logical segment(s).
Change the BUM Replication Mode from Hierarchical Two-Tier to Head-End Replication
Note: Head-End Replication forces the source transport node to replicate broadcast frames directly to all target VTEPs, completely bypassing the broken proxy host.
To permanently resolve the gateway mismatch, ensure all TEP VMkernel interfaces on any given ESXi host reside within a single IP subnet