Contributor
Contributor

NSX-V 6.4.5 DLR cannot ping external network via Edge Gateway

Jump to solution

I have the following configuration in my setup:

NSX Edge --- uplink port --- 10.10.144.15
         --- Transit network --- 192.168.9.1

NSX DLR --- uplink port --- 192.168.9.2
        --- Logical switch 1 --- 172.18.10.1
        --- Logical switch 2 --- 172.18.20.1

BGP routing is enabled between the DLR and ESG for dynamic routing.

Following is the routing configuration on:

ESG

ESG - ip route show

DLR

DLR - ip route show

 

There is a proxy VM on the 10.10.114.0/24 network and its IP is 10.10.114.11. I am able to ping this VM from ESG, but not from DLR.

From DLR I am able to ping 10.10.114.15(ESG's IP) but not the proxy VM nor the gateway.

What could be the issue?

NOTE:

  • The firewall on both DLR and ESG has been set to 'allow'.

  • The DLR has the default route configured
  • The edge has the SNAT configured for the VMs to go out and reach the internet.
Tags (2)
1 Solution

Accepted Solutions

It looks that you are having a problem with the routing from the Proxy to the Edge.

You have a DG that moves traffic from the EDGE to the outside network.

Maybe there is a route missing in your router that says something like this:

172.18.10.0/24 go to 10.10.144.15

172.18.20.0/24 go to 10.10.144.15

Try to traceroute from the proxy or other vm in that network and you will see.

Hope that helps

Triple VCIX (CMA-NV-DCV) | vExpert | MCSE | CCNA

View solution in original post

0 Kudos
4 Replies
Contributor
Contributor

Hi,

Sorry my bad, that I did not mention the version of NSX. I am using NSX 6.4.5 and I have the defauilt route configured on DLR and I also have SNAT configured on the gateway.

0 Kudos

It looks that you are having a problem with the routing from the Proxy to the Edge.

You have a DG that moves traffic from the EDGE to the outside network.

Maybe there is a route missing in your router that says something like this:

172.18.10.0/24 go to 10.10.144.15

172.18.20.0/24 go to 10.10.144.15

Try to traceroute from the proxy or other vm in that network and you will see.

Hope that helps

Triple VCIX (CMA-NV-DCV) | vExpert | MCSE | CCNA

View solution in original post

0 Kudos
Contributor
Contributor

In SNAT I was using the proxy IP address as the translated address. I changed it to the ESG's uplink IP address and it started to work. Thanks NicolasAlauzet​ for the pointer.