Holodeck 9.1 deployment fails during nested ESXi customization due to network isolation
search cancel

Holodeck 9.1 deployment fails during nested ESXi customization due to network isolation

book

Article ID: 449169

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Nested ESXi VMkernel interface (vmk0) has a valid static IP
  • ESXi can see the HoloRouter MAC in its neighbour table, but vmkping to the gateway fails with 100% packet loss.
  • Cisco ACI endpoint table does not learn the nested ESXi MAC address, even though the outer VM NIC MAC is learned.
  • Traffic captures show ARP requests leaving the nested host but no responses returning.

Environment

Holodeck 9.1.0.0
VMware Cloud Foundation (VCF) 9.1
Cisco ACI VMM Integrated Environment

Cause

This issue occurs when MAC Learning and Promiscuous Mode are simultaneously enabled on a trunk portgroup in a nested virtualization environment. In some Cisco ACI VMM integrations, the fabric fails to update the endpoint table for "MAC-behind-MAC" scenarios if the L2 security policies are not explicitly tuned for nested traffic.

Resolution

  1. Log in to the vCenter Server.
  2. Navigate to the Distributed Switch and select the trunk portgroup used for Holodeck deployment. 
  3. Go to Settings > Edit.
  4. Navigate to Advanced.
  5. Set MAC Learning to Disabled.
  6. Ensure Promiscuous Mode, MAC Address Changes, and Forged Transmits remain set to Accept.
  7. Restart the Holodeck deployment.

Additional Information

Disabling MAC learning allows the portgroup to rely on Promiscuous Mode for nested traffic, which often resolves endpoint learning delays in ACI fabrics.
Intermittent Connectivity Issues to Virtual Machines in Cisco ACI Environments
Subscribe to this article to receive updates on fix status: https://knowledge.broadcom.com/external/article/275360.