Edge TEP tunnels down after changing uplink profile in VMware NSX
search cancel

Edge TEP tunnels down after changing uplink profile in VMware NSX

book

Article ID: 448468

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • TEP tunnels transition to "Down" immediately after an uplink profile change.
  • get bfd-sessions on the Edge CLI shows BFD sessions in INIT or DOWN state.
  • Ping between Edge TEP and Host TEP or Gateway fails.
  • BGP or North-South traffic may remain functional if using different physical links/VLANs.

 

Environment

VMware NSX

Cause

The physical switch ports connected to the Edge uplinks are not configured to allow the Transport VLAN ID defined in the new Uplink Profile. When the profile is swapped, the Edge begins tagging traffic with the new VLAN, which is then pruned/dropped by the physical switch.

Resolution

  1. Verify the Transport VLAN ID configured in the active Uplink Profile under System > Fabric > Profiles > Uplink Profiles.
  2. Log in to the physical switch connected to the Edge uplinks.
  3. Add the required TEP VLAN to the allowed VLAN list on the physical trunk ports.
  4. On the Edge CLI, verify connectivity by pinging the TEP gateway: ping <Gateway_IP> interface <TEP_Interface_Name>
  5. If tunnels remain down, verify that Mac Address Changes and Forged Transmits are set to Accept on the vSphere Distributed Switch port groups (for Virtual Edges).


Note : If the issue persists, contact Broadcom Support. For software downloads, visit the Broadcom Support Portal.

Additional Information

NSX Edge MPA Connectivity Down
NSX Edge shows configuration status as MPA Connectivity Down
NSX Edge node MPA Connectivity Down state due to expired transport node certificate