VCF 9.1 transport node preparation fails due to blocked DHCP ports 67 and 68
search cancel

VCF 9.1 transport node preparation fails due to blocked DHCP ports 67 and 68

book

Article ID: 449529

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Transport nodes report a "DOWN" status following 9.1 installation process.
While the installer may allow the process to continue with a "warning" message, the transport nodes remains in 'Down' status and unable to participate in the overlay network.

Tunnel Endpoint (TEP) IP addresses are not assigned when using the "DHCP" option.
Communication between the transport node overlay network and the external DHCP network is unsuccessful.

Environment

VMware Cloud Foundation 9.1
VMware NSX

Cause

Network communication for DHCP traffic is blocked by upstream firewalls or security policies.

Specifically, UDP ports 67 and 68 are not permitted between the transport node overlay network and the external DHCP server, preventing the nodes from receiving TEP IP addresses.

Resolution

  1. Coordinate with the network security team to validate and allow UDP ports 67 and 68 (bidirectional) between the transport node overlay network and the DHCP server network.
  2. Verify that any DHCP relay agents (IP Helpers) are correctly configured on the top-of-rack (ToR) switches for the overlay VLAN.
  3. Log in to the NSX Manager UI.
  4. Navigate to System > Fabric > Nodes > Host Transport Nodes.
  5. Select the affected hosts and click Configure NSX or Sync/Resolve to re-trigger the configuration.
  6. Verify that the transport nodes now receive a valid TEP IP address and report a "Success" or "Up" status.

Additional Information

For general VCF installation troubleshooting, see Contact Broadcom Support.
To download the latest VCF releases, visit Broadcom Products and Software.