Standby SD-WAN Edge in an Enhanced HA blocks its WAN link
search cancel

Standby SD-WAN Edge in an Enhanced HA blocks its WAN link

book

Article ID: 320674

calendar_today

Updated On:

Products

VMware VMware SD-WAN by VeloCloud

Issue/Introduction

Symptoms:

On a customer site deployed with an Enhanced High-Availability (HA) topology, a WAN link connected to the VMware SD-WAN Edge in a Standby role may show as down on the VMware SASE Orchestrator and not pass customer traffic even though the Edge's WAN interface where the WAN link is connected is up.


Environment

VMware SD-WAN by VeloCloud
VMware SD-WAN

Cause

This issue is caused by Issue #97559. 

In Enhanced HA, when an Edge assumes the role of Standby, the following events should occur in sequence:
1. The Standby Edge blocks all ports.
2. The Standby Edge then detects that it is deployed in Enhanced HA and unblocks its WAN ports to pass traffic.

When this issue occurs, Event 1, the initial port blocking takes an unexpectedly long time to complete and the follow-up Event 2, the unblocking of all WAN ports is completed prior to the completion of Event 1. And then Event 1 completes and thus the final state is all WAN ports are blocked on the Standby Edge.

Resolution

Issue 97559 is resolved in SD-WAN edge releases:
  • 4.5.1 RU3 (R451-20221213-GA) and above
  • 4.5.2 (R452-20231025-GA) and above
  • 5.0.1.3 (R5013-20230322-GA) and above

For information on how to upgrade please check the following article: VMware SD-WAN Software Upgrade FAQs

Workaround:
An HA failover that promotes the Standby Edge to Active brings up the HA Edge's WAN link(s).