{"id":1054,"date":"2022-04-27T08:42:21","date_gmt":"2022-04-27T07:42:21","guid":{"rendered":"https:\/\/vminded.com\/?p=1054"},"modified":"2022-04-27T08:42:23","modified_gmt":"2022-04-27T07:42:23","slug":"nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting","status":"publish","type":"post","link":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/","title":{"rendered":"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting"},"content":{"rendered":"\n<p>In a recent <a href=\"https:\/\/vminded.com\/index.php\/2021\/12\/15\/nsx-manager-standalone-ui-for-vmc-on-aws\/\" target=\"_blank\" rel=\"noreferrer noopener\">post<\/a> I have talked about the NSX Manager Standalone UI access which was released in <a href=\"https:\/\/www.vmware.com\/fr\/products\/vmc-on-aws.html\" target=\"_blank\" rel=\"noreferrer noopener\">VMware Cloud on AWS<\/a> in version 1.16. <\/p>\n\n\n\n<p>This capability is now permitting customer to access a very useful feature called <a href=\"https:\/\/docs.vmware.com\/en\/VMware-NSX-T-Data-Center\/3.1\/administration\/GUID-A85621BC-1CFD-4703-846A-2B3D36E7ABAC.html\" target=\"_blank\" rel=\"noreferrer noopener\">Traceflow<\/a> that many NSX customers are familiar with and which allows them to troubleshoot connectivity issues in their SDDC.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is Traceflow and  how does it work?<\/h2>\n\n\n\n<p>VMware Cloud on AWS customers can leverage Traceflow to inspect the path of a packet from any<strong> source<\/strong> to any <strong>destination <\/strong>Virtual Machines running into the SDDC. In addition, Traceflow provides visibility for external communication over VMware <strong><a href=\"https:\/\/blogs.vmware.com\/networkvirtualization\/2020\/09\/vmware-transit-connect-simplifying-networking-for-vmc.html\/\" target=\"_blank\" rel=\"noreferrer noopener\">Transit Connect<\/a><\/strong> or the Internet.<\/p>\n\n\n\n<p>Traceflow allows you to inject a packet into the network and monitor its flow across the network. This flow allows you to monitor your network path and identify issues such as bottlenecks or disruptions.<\/p>\n\n\n\n<p>Traceflow observes the marked packet as it traverses the overlay network, and each packet is monitored as it crosses the overlay network until it reaches a destination guest VM or an Edge uplink. Note that the injected marked packet is never actually delivered to the destination guest VM.<\/p>\n\n\n\n<p>Let&#8217;s see what it can do to help <strong>gaining visibility <\/strong>and  <strong>troubleshooting<\/strong> networking <strong>connectivity<\/strong> in a VMC on AWS SDDC.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-troubleshooting-connectivity-between-an-sddc-and-a-native-vpc-over-a-vtgw-tgw\">Troubleshooting Connectivity between an SDDC and a native VPC over a vTGW\/TGW.<\/h2>\n\n\n\n<p>First let&#8217;s have a look at the diagram of this lab.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1014\" height=\"605\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png\" alt=\"\" class=\"wp-image-1535\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png 1014w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02-300x179.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02-768x458.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>In my lab, I have deployed two SDDCs: SDDC1 and SDDC2 in two different regions and have attached them together within an SDDC Group. As they are in two different region two Virtual Transit Connect are required. I have two VMs deployed in the SDDC1, Deb10-App01 (172.18.12.100) and Deb10-Web001 (172.18.11.100).<\/p>\n\n\n\n<p> I have also deployed a native VPC (IP: 172.20.2.0\/24) attached to the SDDCs group through a TGW peered to the vTGW. I then have deployed two VMs in the attached VPC  with IPs 172.20.2.148 and .185.<\/p>\n\n\n\n<p>In this example, the trafic I want to gain visibility on will flow over the <strong>vTGW<\/strong> (VMware Managed transit Gateway) and the native<strong> Transit Gateway<\/strong>&#8211;<strong>TGW<\/strong> which is peered to it.  <\/p>\n\n\n\n<p><a href=\"https:\/\/blogs.vmware.com\/cloud\/2021\/12\/02\/seamlessly-connect-your-sddcs-and-vpcs-with-aws-transit-gateway-intra-region-peering\/\" target=\"_blank\" rel=\"noreferrer noopener\">Peering a vTGW to a native AWS Transit Gateway<\/a> is a new capability we recently introduced. We can peer them in different region as well as in same region. If you want to know more how to setup this architecture, have a look at my post where I describe the all process.<\/p>\n\n\n\n<p>Once all connectivity is established, I have tested ping connectivity between the VM <strong>Deb10-App01 <\/strong>(172.18.12.100) running on a Compute segment in SDDC1 to the <strong>EC2 instance <\/strong>(172.20.2.148) running in the native VPC (172.20.2.0\/24).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.52.59-1024x854.png\" alt=\"\" class=\"wp-image-1449\" width=\"594\" height=\"495\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.52.59-1024x854.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.52.59-300x250.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.52.59-768x641.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.52.59-1200x1001.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.52.59.png 1534w\" sizes=\"auto, (max-width: 594px) 85vw, 594px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Let&#8217;s launch the Traceflow from the NSX Manager UI. After connecting to the interface, the tool is accessible under the <strong>Plan &amp; Troubleshoot<\/strong> menu.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"492\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.57.36-1024x492.png\" alt=\"\" class=\"wp-image-1451\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.57.36-1024x492.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.57.36-300x144.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.57.36-768x369.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.57.36-1200x576.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-18.57.36.png 1420w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Select Source machine in SDDC<\/h3>\n\n\n\n<p>In order to gain visibility under the traffic between both VMs, I have first selected the VM in the SDDC in the left Menu which is where you can define the Source machine.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"749\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09-1024x749.png\" alt=\"\" class=\"wp-image-1453\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09-1024x749.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09-300x219.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09-768x562.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09-1536x1123.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09-1200x878.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.00.09.png 1734w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Select Destination Machine in the native VPC<\/h3>\n\n\n\n<p>In order to select the destination <strong>EC2 instance<\/strong> running in the native VPC, I have had to select <strong>IP &#8211; Mac\/ Layer 3<\/strong> instead of Virtual Machine.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"590\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.11.27.png\" alt=\"\" class=\"wp-image-1455\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.11.27.png 1000w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.11.27-300x177.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.11.27-768x453.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Displaying and Analyzing the Results<\/h3>\n\n\n\n<p>The traceflow is ready to be started!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"623\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2-1024x623.png\" alt=\"\" class=\"wp-image-1515\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2-1024x623.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2-300x183.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2-768x467.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2-1536x935.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2-1200x730.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.18.04-2.png 2024w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>The Analysis start immediately after clicking on the <strong>Trace<\/strong> button.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.16.39.png\" alt=\"\" class=\"wp-image-1460\" width=\"404\" height=\"294\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.16.39.png 838w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.16.39-300x218.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.16.39-768x559.png 768w\" sizes=\"auto, (max-width: 404px) 85vw, 404px\" \/><\/figure><\/div>\n\n\n\n<p>After a few seconds, the results are displayed. The NSX\u00a0interface graphically displays the trace route based on the parameters I set (IP address type, traffic type, source, and destination). This display page also enables you to <strong>edit<\/strong> the parameters, <strong>retrace <\/strong>the traceflow, or <strong>create a new one<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04-1024x569.png\" alt=\"\" class=\"wp-image-1456\" width=\"630\" height=\"350\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04-1024x569.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04-300x167.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04-768x427.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04-1536x854.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04-1200x667.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.10.04.png 1942w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><figcaption>Traffic flow diagram with the hops<\/figcaption><\/figure>\n\n\n\n<p>The screen is split into two <strong>sections<\/strong>. <\/p>\n\n\n\n<p>First section, on the top, is showing the diagram with the multiple hops that was crossed by the traffic. Here we can see that the packets has first flowed over the CGW, then it has reached the Intranet Uplink of the EDGE, it hit the vTGW (Transit Connect) and it has finally crossed the native TGW.<\/p>\n\n\n\n<p>We can see that the MAC address of the destination has been collected on the top near the Traceflow &#8216;title&#8217;. <\/p>\n\n\n\n<p>The second section detailed each and every steps followed by the packets with the associated timestamps. The first column shows the number of physical Hops.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"520\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-1024x520.png\" alt=\"\" class=\"wp-image-1465\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-1024x520.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-300x152.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-768x390.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-1536x779.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-2048x1039.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.20.11-1200x609.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>The final step show the packet has been correctly delivered to the TGW.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"119\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-1024x119.png\" alt=\"\" class=\"wp-image-1467\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-1024x119.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-300x35.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-768x89.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-1536x178.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-2048x237.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.21.33-1200x139.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>We can confirm that the Distributed Firewall (DFW) have been enforced and were correctly configured :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"49\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26-1024x49.png\" alt=\"\" class=\"wp-image-1473\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26-1024x49.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26-300x14.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26-768x37.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26-1536x73.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26-1200x57.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.31.26.png 1716w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>To confirm which Distributed FW rule have been enforced, you can check on the console the corresponding rule by searching it by the rule ID:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"379\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-1024x379.png\" alt=\"\" class=\"wp-image-1474\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-1024x379.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-300x111.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-768x284.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-1536x568.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-2048x758.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.34.55-1200x444.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Same thing applies for the Edge Firewall for North South Trafic.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"72\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-1024x72.png\" alt=\"\" class=\"wp-image-1477\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-1024x72.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-300x21.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-768x54.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-1536x108.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-2048x144.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.09-1200x85.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Again I have checked the Compute Gateway Firewall rule to confirm it picked the right one and that it was well configured.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"185\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-1024x185.png\" alt=\"\" class=\"wp-image-1478\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-1024x185.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-300x54.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-768x139.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-1536x278.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-2048x370.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-25-at-19.38.32-1200x217.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Let&#8217;s now do a test with a<strong><a href=\"https:\/\/docs.vmware.com\/en\/VMware-Cloud-on-AWS\/services\/com.vmware.vmc-aws-networking-security\/GUID-5AF45CE6-FA53-45C0-83E5-25F8E3A055E9.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Route Based VPN<\/a><\/strong> to see the difference.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting Connectivity between an SDDC and a TGW via a RB VPN<\/h2>\n\n\n\n<p>Now instead of using the vTGW to TGW peering, I have established a Route Based VPN directly to the native Transit GW in order to avoid flowing over the vTGW.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"635\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-1024x635.png\" alt=\"\" class=\"wp-image-1496\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-1024x635.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-300x186.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-768x476.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-1536x953.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-2048x1270.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.26.46-1200x744.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>I have enable the RB VPN from the Console:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"339\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-1024x339.png\" alt=\"\" class=\"wp-image-1486\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-1024x339.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-300x99.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-768x254.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-1536x509.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-2048x678.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.44.32-1200x398.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>I have enable only the first one.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"39\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-1024x39.png\" alt=\"\" class=\"wp-image-1489\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-1024x39.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-300x12.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-768x30.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-1536x59.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-2048x79.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.37.33-1200x46.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>After a few minutes the<strong><a href=\"https:\/\/www.cloudflare.com\/learning\/security\/glossary\/what-is-bgp\/\" target=\"_blank\" rel=\"noreferrer noopener\"> BGP<\/a><\/strong> session is established.<\/p>\n\n\n\n<p>The VPN Tunnel in AWS shows 8 routes have been learned in the BGP Session.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"40\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-1024x40.png\" alt=\"\" class=\"wp-image-1487\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-1024x40.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-300x12.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-768x30.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-1536x60.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-2048x80.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.49.18-1200x47.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>I just need to remove the static route in the native TGW route table to avoid asymmetric traffic.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"204\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-1024x204.png\" alt=\"\" class=\"wp-image-1498\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-1024x204.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-300x60.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-768x153.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-1536x306.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-2048x408.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-08.45.10-1-1200x239.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>The 172.18.12.0\/24 where my Virtual Machine runs is now learned from the BGP session.<\/p>\n\n\n\n<p>Let&#8217;s start the analysis agains by clicking the Retrace button.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"90\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36-1024x90.png\" alt=\"\" class=\"wp-image-1499\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36-1024x90.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36-300x26.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36-768x68.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36-1536x135.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36-1200x106.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.36.png 1678w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><figcaption>Click on Retrace button to relaunch the analysis on the same Source and Destination<\/figcaption><\/figure>\n\n\n\n<p>Click Proceed to start the new request.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.43.png\" alt=\"\" class=\"wp-image-1501\" width=\"502\" height=\"176\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.43.png 908w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.43-300x106.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.02.43-768x271.png 768w\" sizes=\"auto, (max-width: 502px) 85vw, 502px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>The new traceflow request result displays. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.16-1024x728.png\" alt=\"\" class=\"wp-image-1488\" width=\"630\" height=\"447\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.16-1024x728.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.16-300x213.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.16-768x546.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.16.png 1182w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>This time the packet used  the <strong>Internet Uplink<\/strong> and the <strong>Internet Gateway<\/strong> of the Shadow VPC managed by VMware where the SDDC is deployed. The observations show that packets were successfully delivered to both the NSX-Edge-0 through IPSEC and to the Internet Gateway (igw). <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"618\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-1024x618.png\" alt=\"\" class=\"wp-image-1510\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-1024x618.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-300x181.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-768x463.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-1536x927.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-2048x1236.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-09.04.37-1-1200x724.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting Firewall rules<\/h2>\n\n\n\n<p>Last thing you can test with Traceflow is how to troubleshoot connectivity when a Firewall rule is blocking a packet.<\/p>\n\n\n\n<p>For this scenario, I have changed the Compute Gateway Firewall rule to drop the packets.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"77\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-1024x77.png\" alt=\"\" class=\"wp-image-1503\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-1024x77.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-300x22.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-768x58.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-1536x115.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-2048x154.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.40.50-1200x90.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>I have started the request again and the result is now showing a red exclamation mark.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"422\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-1024x422.png\" alt=\"\" class=\"wp-image-1509\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-1024x422.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-300x124.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-768x317.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-1536x633.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-2048x844.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.42.37-1-1200x495.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><figcaption>The reason of the Packet Dropped is a Firewall Rule<\/figcaption><\/figure>\n\n\n\n<p>The details confirmed it was dropped by the Firewall rule and it displayed the ID of the rule.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"75\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-1024x75.png\" alt=\"\" class=\"wp-image-1511\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-1024x75.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-300x22.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-768x56.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-1536x112.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-2048x150.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-26-at-10.49.56-1200x88.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>That concludes this blog post on how to easily troubleshoot your network connectivity  by leveraging the <strong>Traceflow<\/strong> tool from the <strong>NSX Manager UI<\/strong> in <strong><a href=\"https:\/\/www.vmware.com\/fr\/products\/vmc-on-aws.html\" target=\"_blank\" rel=\"noreferrer noopener\">VMware Cloud on AWS<\/a><\/strong>.<\/p>\n\n\n\n<p>Thanks for visiting my blog! If you have any questions, please leave a comment below.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a recent post I have talked about the NSX Manager Standalone UI access which was released in VMware Cloud on AWS in version 1.16. This capability is now permitting customer to access a very useful feature called Traceflow that many NSX customers are familiar with and which allows them to troubleshoot connectivity issues in &hellip; <a href=\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-1054","post","type-post","status-publish","format-standard","hentry","category-vmconaws"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting - vminded.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting - vminded.com\" \/>\n<meta property=\"og:description\" content=\"In a recent post I have talked about the NSX Manager Standalone UI access which was released in VMware Cloud on AWS in version 1.16. This capability is now permitting customer to access a very useful feature called Traceflow that many NSX customers are familiar with and which allows them to troubleshoot connectivity issues in &hellip; Continue reading &quot;NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\" \/>\n<meta property=\"og:site_name\" content=\"vminded.com\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-27T07:42:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-27T07:42:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png\" \/>\n<meta name=\"author\" content=\"Christophe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christophe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\"},\"author\":{\"name\":\"Christophe\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"headline\":\"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting\",\"datePublished\":\"2022-04-27T07:42:21+00:00\",\"dateModified\":\"2022-04-27T07:42:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\"},\"wordCount\":1135,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png\",\"articleSection\":[\"VMConAWS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\",\"url\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\",\"name\":\"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting - vminded.com\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png\",\"datePublished\":\"2022-04-27T07:42:21+00:00\",\"dateModified\":\"2022-04-27T07:42:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage\",\"url\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png\",\"contentUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png\",\"width\":1014,\"height\":605},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/vminded.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vminded.com\/#website\",\"url\":\"https:\/\/vminded.com\/\",\"name\":\"vminded.com\",\"description\":\"feed your mind with virtual thoughts\",\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/vminded.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\",\"name\":\"Christophe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"caption\":\"Christophe\"},\"logo\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/vminded.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting - vminded.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/","og_locale":"en_US","og_type":"article","og_title":"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting - vminded.com","og_description":"In a recent post I have talked about the NSX Manager Standalone UI access which was released in VMware Cloud on AWS in version 1.16. This capability is now permitting customer to access a very useful feature called Traceflow that many NSX customers are familiar with and which allows them to troubleshoot connectivity issues in &hellip; Continue reading \"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting\"","og_url":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/","og_site_name":"vminded.com","article_published_time":"2022-04-27T07:42:21+00:00","article_modified_time":"2022-04-27T07:42:23+00:00","og_image":[{"url":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png","type":"","width":"","height":""}],"author":"Christophe","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christophe","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#article","isPartOf":{"@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/"},"author":{"name":"Christophe","@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"headline":"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting","datePublished":"2022-04-27T07:42:21+00:00","dateModified":"2022-04-27T07:42:23+00:00","mainEntityOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/"},"wordCount":1135,"commentCount":0,"publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png","articleSection":["VMConAWS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/","url":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/","name":"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting - vminded.com","isPartOf":{"@id":"https:\/\/vminded.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png","datePublished":"2022-04-27T07:42:21+00:00","dateModified":"2022-04-27T07:42:23+00:00","breadcrumb":{"@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#primaryimage","url":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png","contentUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/04\/Screenshot-2022-04-27-at-09.36.02.png","width":1014,"height":605},{"@type":"BreadcrumbList","@id":"https:\/\/vminded.com\/index.php\/2022\/04\/27\/nsx-traceflow-in-vmc-on-aws-for-self-service-traffic-troubleshooting\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vminded.com\/"},{"@type":"ListItem","position":2,"name":"NSX Traceflow in VMC on AWS for self-service traffic Troubleshooting"}]},{"@type":"WebSite","@id":"https:\/\/vminded.com\/#website","url":"https:\/\/vminded.com\/","name":"vminded.com","description":"feed your mind with virtual thoughts","publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vminded.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a","name":"Christophe","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","caption":"Christophe"},"logo":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/vminded.com"]}]}},"_links":{"self":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/1054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/comments?post=1054"}],"version-history":[{"count":64,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/1054\/revisions"}],"predecessor-version":[{"id":1545,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/1054\/revisions\/1545"}],"wp:attachment":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/media?parent=1054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/categories?post=1054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/tags?post=1054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}