This article addresses troubleshooting steps for scenarios where Source NAT (SNAT) rules on a VMware NSX Edge Gateway fail to evaluate correctly, resulting in traffic matching incorrect or unintended rules.
VMware NSX
The SNAT rule evaluation fails when the "Translated IP" defined in the SNAT rule resides within the same subnet as the Edge Gateway’s Logical Router (LR) port interface. This address overlap creates a routing and datapath conflict, causing the NSX Edge to bypass the primary SNAT rule and match subsequent rules with the same source IP criteria.
To resolve this issue, assign a "Translated IP" address that is outside the IP address range of the LR port interface.
Check the active edge node interface configurations to identify the subnet of the downlink interface.
get logical-router <LR-UUID> interfaceCompare the "Translated IP" used in the problematic SNAT rule against the subnets identified in step 1.
Modify SNAT Rule:
After updating the rule, verify the traffic matches the intended SNAT rule by performing a new connection test or using Traceflow to confirm the translation is applied correctly.
For further assistance or to speak with a customer representative, see Contact Support. Scroll to the bottom of the page and click on your respective region.