Avi VIP reachability loss after vMotion due to missing VLAN tagging on ESXi uplinks
search cancel

Avi VIP reachability loss after vMotion due to missing VLAN tagging on ESXi uplinks

book

Article ID: 448489

calendar_today

Updated On:

Products

VMware vSphere ESXi VMware vCenter Server VMware Avi Load Balancer

Issue/Introduction

  • Traffic to Avi Virtual Service (VIP) IPs stops immediately after a Service Engine (SE) VM migrates via vMotion.
  • VIPs are unreachable via ICMP or application protocols from upstream L3 switches.
  • Packet captures confirm the SE VM sends Gratuitous ARP (GARP) or RARP packets, but the physical network does not receive them on the destination host's ports. 

Environment

VMware ESXi 

VMware Advanced Load Balancer

Cause

The destination ESXi host physical switch ports (uplinks) lack the necessary VLAN tagging or trunking configuration for the Avi VIP network.

While the source host correctly permits the VLAN, the destination host drops the tagged egress traffic because the physical port is misconfigured (e.g., set to the wrong access VLAN or missing the VLAN ID in the trunk allowed list).

Resolution

Workaround: 

Ensure consistent VLAN trunking across all ESXi host uplinks within the cluster to permit Avi VIP traffic.

  1. Identify the destination ESXi host and its active physical vmnics.
  2. Review the physical switch port configuration connected to those uplinks.
  3. Verify that all VLAN IDs used by the Avi VIP and Data networks are explicitly permitted on the trunk.
  4. Confirm that the Notify Switches policy is set to Yes in the vSphere Distributed Switch or Standard Switch Port Group properties.
  5. If a configuration mismatch exists, update the physical switch ports to match the source host configuration.
  6. Test by performing a manual vMotion and running a continuous ping to the VIP.