An IPsec VPN tunnel fails to establish in VMware NSX when the local endpoint is configured on a loopback interface and the NSX Edge is set to responder mode.
Symptoms:
VMware NSX
The tunnel failure is caused by a lack of initiation from the remote peer. When migrating an existing IPsec VPN configuration from a Virtual IP (VIP) to a loopback interface as the local endpoint, the remote peer may fail to initiate the IKE negotiation if the configuration update results in a mismatch or stale phase 1 parameters.
To resolve this issue, ensure that the remote peer is correctly configured to initiate the IKE negotiation toward the new loopback address of the NSX Edge.
get ipsecvpn ikesa
get ipsecvpn ipsecsa