SNAT Rule Evaluation Failure Due to Translated IP Subnet Overlap on Edge Gateway
search cancel

SNAT Rule Evaluation Failure Due to Translated IP Subnet Overlap on Edge Gateway

book

Article ID: 452117

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

This article addresses troubleshooting steps for scenarios where Source NAT (SNAT) rules on a VMware NSX Edge Gateway fail to evaluate correctly, resulting in traffic matching incorrect or unintended rules.

  • SNAT rules fail to apply to intended traffic.
  • Traffic is matched against incorrect or broader NAT rules.
  • The intended SNAT rule appears in a "failed" state within the NSX Manager.




Environment

VMware NSX

Cause

The SNAT rule evaluation fails when the "Translated IP" defined in the SNAT rule resides within the same subnet as the Edge Gateway’s Logical Router (LR) port interface. This address overlap creates a routing and datapath conflict, causing the NSX Edge to bypass the primary SNAT rule and match subsequent rules with the same source IP criteria.

Resolution

To resolve this issue, assign a "Translated IP" address that is outside the IP address range of the LR port interface.

  1. Check the active edge node interface configurations to identify the subnet of the downlink interface.

    • Run get logical-router <LR-UUID> interface
  2. Compare the "Translated IP" used in the problematic SNAT rule against the subnets identified in step 1.

  3. Modify SNAT Rule:

    • Navigate to Networking > NAT in the NSX Manager UI.
    • Select the relevant Tier-1 Gateway.
    • Edit the SNAT rule that is in a failed state.
    • Update the Translated IP field to an address outside of the identified LR port subnet.
    • Save the configuration.
  4. After updating the rule, verify the traffic matches the intended SNAT rule by performing a new connection test or using Traceflow to confirm the translation is applied correctly.

Additional Information

For further assistance or to speak with a customer representative, see Contact Support. Scroll to the bottom of the page and click on your respective region.