This article provides guidance on troubleshooting intermittent connection failures and timeouts when pods or proxies attempt to communicate with internal Kubernetes Service VIPs (e.g., #.#.#.#) within the Supervisor cluster.
upstream timed out or Connection reset by peer during SSL/TLS handshaking.Intermittent TLS handshake failures to internal Service VIPs in a VKS Supervisor cluster are frequently caused by MTU mismatch issues or packet fragmentation across the NSX Geneve overlay network.
To diagnose and resolve, follow these steps:
curl -kv https://#.#.#.#:#For detailed instructions on capturing network traffic for analysis, review the documentation on retrieving support bundles and logs. To speak with a customer representative or a Support Engineer, see . Scroll to the bottom of the page and click on your respective region.