Troubleshooting Supervisor Cluster VIP Reachability with Subnet Overlap in VKS
search cancel

Troubleshooting Supervisor Cluster VIP Reachability with Subnet Overlap in VKS

book

Article ID: 451121

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

Symptoms:

  • Supervisor Cluster Virtual IP is unreachable after successful deployment in VPC (DTGW) environments
  • The VPC External IP blocks and Supervisor Cluster Management networks share a subnet.

Environment

VMware vSphere Kubernetes Service

Cause

Routing conflict caused by overlapping subnets between VPC External IP Block and Supervisor Cluster Management Network.

Resolution

 

  • Identify existing network configuration and confirm if External IP Block and Management Network share a subnet/VLAN.
  • Define a new, dedicated subnet for the External IP Block that does not overlap with the Management network.
  • Reconfigure the VPC (DTGW) external connection settings to use this dedicated, non-overlapping subnet.
  • Ensure proper VLAN tagging is implemented to isolate management traffic from external workload traffic.
  • Perform a connectivity test to the Supervisor VIP to verify reachability.

 

Additional Information

Standard architecture with separated Management and VPC External network in DTGW

https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/vsphere-supervisor-installation-and-configuration/supervisor-networking-with-virtual-private-clouds/supervisor-architecture-with-vpc-networking.html