Traffic Drops at DVS Level When MAC Address Change and MAC Learning Are Enabled. Unable to ping edge from cloud environment
search cancel

Traffic Drops at DVS Level When MAC Address Change and MAC Learning Are Enabled. Unable to ping edge from cloud environment

book

Article ID: 449782

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Network traffic originating from an NSX Edge Virtual Machine (VM) is dropped at the vSphere Distributed Switch (DVS) portgroup level and fails to traverse the host physical uplink.

  • Packet captures confirm traffic successfully enters the Edge VM on the Virtual Tunnel Interface (VTI), GRE Tap, and Edge uplink.
  • No traffic is observed when capturing packets on the host physical uplink.
  • Network frames are dropped at the Distributed Virtual Switch (DVS) layer prior to hitting the physical network interface.

Environment

VMware NSX

Cause

Identified that the packet loss at the DVS layer was caused by a settings conflict on the portgroup. Specifically, enabling both MAC Address Change (under Security policy) and MAC Learning at the same time causes the switch to drop frames during processing.

Resolution

  1. Log in to the vCenter Server Client.
  2. Navigate to Networking and locate the affected Distributed Virtual Switch (DVS).
  3. Select the affected DVS Distributed Portgroup.
  4. Right-click the portgroup and select Edit Settings.
  5. Select the Security / MAC Learning configuration section.
  6. Change the MAC Learning status to Disabled.
  7. Click OK to save changes.
  8. Validate packet flow across the host uplink.

 

Note: If this configuration is specific to a third-party vendor, we recommend consulting with the respective vendor to review their official guidance and supported limits before proceeding with the setup.

Additional Information

For more information refer KB- https://knowledge.broadcom.com/external/article/438391