Error: HCX site pairing flapping due to underlying VPN or WAN connectivity failure
search cancel

Error: HCX site pairing flapping due to underlying VPN or WAN connectivity failure

book

Article ID: 448499

calendar_today

Updated On:

Products

VMware HCX

Issue/Introduction

HCX site pairing and Interconnect tunnels show a "disconnected" status. This typically occurs when the underlying transport layer, such as an IPsec VPN or WAN connection, experiences instability or a service outage.

 

Environment

  • VMware HCX
  • VMware Cloud on AWS (VMC)

Cause

The issue is caused by a failure in the network infrastructure between the source and destination sites. HCX services rely on a stable IPsec VPN or Direct Connect tunnel as the transport layer for communication.

Resolution

Follow these steps to diagnose and resolve the connectivity issue:

  1. Perform a traceroute from the HCX Manager (Connector or Cloud) to the remote HCX Manager IP address.
  2. Review the traceroute results to identify where the path terminates. If the trace stops at a local firewall or a public gateway, investigate the network device for outages.
  3. Verify the status of the IPsec VPN service or Direct Connect circuit with your networking team or service provider.
  4. Once the underlying network service is restored, monitor the HCX site pairing.
  5. If the HCX tunnels do not automatically restore after the network is stable, restart the HCX Interconnect (IX) appliances from the HCX Service Mesh interface.

Additional Information

For more detailed diagnostic steps, see HCX Site Pairing Connectivity Diagnostics.