Connectivity issues between VMs on different ESXi hosts due to incorrect MAC address configuration.
search cancel

Connectivity issues between VMs on different ESXi hosts due to incorrect MAC address configuration.

book

Article ID: 448433

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESXi

Issue/Introduction

  • NetScaler health monitor reports: "Failure - Time out during TCP connection establishment stage."
  • Real-time packet captures on the NetScaler (nstcpdump.sh) show the SNIP transmitting SYN packets, but no SYN-ACK is received from the backend server.
  • Backend VMs receive ICMP requests but send replies to an incorrect MAC address that does not belong to the NetScaler SNIP.

Environment

VMware vSphere ESXi

Cause

An incorrect MAC address configuration or stale MAC learning on the physical switch side causes a MAC address mismatch. 

Resolution

To resolve the connectivity issue, follow these steps:

  1. Inspect the MAC address tables on the physical switches connected to the ESXi host uplinks.
  2. Verify the physical switch correctly learns the NetScaler SNIP MAC address on the appropriate ports.
  3. Correct any manual MAC overrides or stale entries in the physical switch configuration.
  4. Clear the ARP table on the backend Guest OS to force a fresh MAC discovery.
  5. Confirm the TCP 3-way handshake completes by running a new packet capture on the NetScaler using: nstcpdump.sh host #### (Replace #### with the backend VM IP).

If the issue persists, open a case with the Broadcom support, see Contact Broadcom support