HCX Interconnect or Network Extension appliances show more than 8 tunnels and report Degraded status
search cancel

HCX Interconnect or Network Extension appliances show more than 8 tunnels and report Degraded status

book

Article ID: 448945

calendar_today

Updated On:

Products

VMware HCX

Issue/Introduction

In VMware HCX environments where Application Path Resiliency (APR) is enabled, users may observe that the Interconnect (IX) or Network Extension (NE) appliances report a Degraded status. Upon inspection, the appliance may display more than the expected 8 tunnels, with several of these tunnels reporting a Down state.

  • HCX IX or NE appliance status is Degraded.
  • The tunnel count exceeds 8 (e.g., 16 or 24 tunnels visible).
  • Multiple tunnels under the appliance are in a Down or inactive state.

Environment

VMware HCX

Cause

By default, enabling APR creates up to 8 transport tunnels between a single source and target uplink IP address pair. The total tunnel count is a factor of the number of configured HCX Uplinks in the Compute Profile:

1 Uplink Pair: 8 tunnels

2 Uplink Pairs: Up to 16 tunnels

3 Uplink Pairs: Up to 24 tunnels

The Degraded status and Down tunnels typically occur due to a Service Mesh misconfiguration or mismatch between the source (Connector) and destination (Cloud) management uplink configurations.

For example, if the HCX Connector is configured with three uplinks while the HCX Cloud site only has one, HCX attempts to establish tunnels for all three paths, but the mismatched paths remain down.

Resolution

To resolve the tunnel inconsistency and clear the Degraded status, must align the uplink configurations across the Service Mesh.

Step 1: Identify the Tunnel Mapping

  1. Log in to the HCX Manager UI.
  2. Navigate to Interconnect > Service Mesh.
  3. Click View Appliances and expand the affected HCX-WAN-IX or HCX-NE appliance.
  4. Review the tunnel breakdown to identify the specific Source and Destination IP addresses for each tunnel.
  5. Determine which specific uplink pairs are failing to establish a connection.

Step 2: Align Compute Profiles

  1. Navigate to Interconnect >Service Mesh > Compute Profiles.
  2. Compare the Network Profiles associated with the "Uplink" role on both the Source and Destination sites.
  3. Ensure the number of available uplinks is consistent on both ends.
  • Example: If the Destination only supports one public/management IP for uplinks, the Source Compute Profile should be adjusted to use only one corresponding uplink.

Step 3: Reconfigure the Service Mesh

  1. After updating the Compute Profiles, return to the Service Mesh tab.
  2. Select the affected Service Mesh and click Reconfigure.
  3. Complete the wizard to push the updated configuration to the appliances.
  4. Verify that the tunnel count now matches the number of active uplink pairs (8 per pair) and that all tunnels report an Up status.

Additional Information

Note: To prevent disruptions to active migration workflows and minimize the impact of Network Extension drops, always perform Service Mesh reconfigurations during a scheduled maintenance window