You observe that Virtual Machines (VMs) attached to public and private Virtual Private Cloud (VPC) subnets cannot communicate outbound. This issue occurs when a distributed transit gateway is implemented with a public network for the VPCs, and default outbound NAT is enabled in the VPC profile. You will see that outbound network connectivity tests from the VPC VMs to the physical network fail, despite no vDefend Firewall being configured for the VPC.
VMware Cloud Foundation
VMware NSX
This issue occurs because the external network for the Distributed Transit Gateway is missing the required VPC External IP Blocks (CIDR/IP Range) configuration. Without this configuration, the VPC VMs cannot successfully route outbound traffic to the physical network.
To resolve this issue, configure the missing IP blocks for the external network:
For additional context and configuration details regarding VPC distributed network connectivity, review the VMware public blog: https://blogs.vmware.com/cloud-foundation/2025/06/25/vpc-distributed-network-connectivity-no-nsx-edge-vms/