{"id":684,"date":"2021-06-24T19:10:50","date_gmt":"2021-06-24T18:10:50","guid":{"rendered":"https:\/\/vminded.com\/?p=684"},"modified":"2021-08-25T19:00:21","modified_gmt":"2021-08-25T18:00:21","slug":"hcx-mon-policy-routes","status":"publish","type":"post","link":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/","title":{"rendered":"HCX MON Policy routes"},"content":{"rendered":"\n<p>I recently have had a question from a customer asking me how the default route is managed into HCX when Mobility Optimized Network is enabled.<\/p>\n\n\n\n<p>Basically when extending multiple VLANS from on-premise to VMware Cloud on AWS by leveraging HCX, you may still want to send egress traffic to an on-premise security device in order for the workloads running in the SDDC to be protected.<\/p>\n\n\n\n<p>I decided to check the way HCX is managing default gateway in my own on-premise lab.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-testing-the-default-gateway-with-mon\">Testing the default gateway with MON<\/h2>\n\n\n\n<p>I have a VMware vSphere lab environment with a 3 nodes VSAN cluster which is link via Internet to an SDDC that I have  deployed with Terraform on our internal CSA Organisation. I have already established site pairing between both sites: <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"850\" height=\"214\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png\" alt=\"\" class=\"wp-image-690\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png 850w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55-300x76.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55-768x193.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>And created a service mesh:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"994\" height=\"348\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.13.43.png\" alt=\"\" class=\"wp-image-691\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.13.43.png 994w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.13.43-300x105.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.13.43-768x269.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>Then I have extended 3 networks to the VMware Cloud on AWS SDDC: APP (VLAN 1712), DB (VLAN 1713) and WEB (VLAN 1711).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"371\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.29.47-1024x371.png\" alt=\"\" class=\"wp-image-685\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.29.47-1024x371.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.29.47-300x109.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.29.47-768x279.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.29.47.png 1111w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><figcaption>Two extended networks are MON enabled: APP and WEB.<\/figcaption><\/figure>\n\n\n\n<p>On the APP network (VLAN 1712), I have deployed one VM (DEB10-APP01) which is running in my VSAN on-premise 3 nodes cluster. This network Extension hasn&#8217;t MON feature enabled.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"216\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.32.46-1024x216.png\" alt=\"\" class=\"wp-image-686\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.32.46-1024x216.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.32.46-300x63.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.32.46-768x162.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.32.46-1200x253.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.32.46.png 1451w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>I have also setup a second subnet called WEB(VLAN 1711). I have another VM (DEB10-WEB01) running there, which have been migrated on a new cluster in VMware Cloud on AWS. This extended network is MON enabled.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"255\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.37.47-1024x255.png\" alt=\"\" class=\"wp-image-689\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.37.47-1024x255.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.37.47-300x75.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.37.47-768x191.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.37.47-1200x299.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.37.47.png 1447w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>I have open a shell session and try to ping the on premise VM DEB10-APP01 from DEB10-WEB01. The trafic is flowing over the internet to my on-premise site through the service mesh:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"734\" height=\"649\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.44.04.png\" alt=\"\" class=\"wp-image-687\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.44.04.png 734w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-17.44.04-300x265.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><figcaption>This is a ping between my VM in SDDC (WEB, 172.11.11.105) to on-premise VM (172.11.12.107, APP)<\/figcaption><\/figure>\n\n\n\n<p>Now I wanted to check where the default route is in the SDDC. Is it going to be the IGW through the T0 router or is it going to be the on-premise gateway?<\/p>\n\n\n\n<p>To check, I have traceroute to the 8.8.8.8.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"502\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.05.37-1024x502.png\" alt=\"\" class=\"wp-image-688\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.05.37-1024x502.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.05.37-300x147.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.05.37-768x377.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.05.37-1200x588.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.05.37.png 1232w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>This is not using my on-premise gateway to egress traffic. However default traffic is going out through the T0 router and internet gateway of the SDDC in AWS.<\/p>\n\n\n\n<p>So now how can I make traffic on a MON enabled network to egress via on-premises?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-the-hcx-mon-policy-routing-works\">How the HCX MON Policy routing works?<\/h2>\n\n\n\n<p>How HCX MON Policy routing works is very simple. When MON is enabled on a network extended segment, HCX adds the gateway IP with \/32 net mask into the SDDC Compute Gateway. For each VM that has MON enabled there is also a \/32 route injection for created or Migrated Virtual Machines. So whenever a Virtual machine on the different segment in the SDDC wants to reach the VM it will allow reachability from SDDC Compute Gateway.<\/p>\n\n\n\n<p>There is a default setting in the Policy routing that is evaluated whenever a destination is not within the SDDC:<\/p>\n\n\n\n<p>If the destination IP is  matched in the policy and allowed by the policy, the trafic is forwarded to the on-premise gateway. If the destination IP is not listed in the policy settings then the traffic is sent to the T0 router in the SDDC and routed accordingly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-changing-the-hcx-mon-policy-routes\">Changing the HCX MON Policy routes<\/h2>\n\n\n\n<p>This setting can however be changed by editing it through a menu available from the ADVANCED tab in the console:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"778\" height=\"145\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.14.04.png\" alt=\"\" class=\"wp-image-693\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.14.04.png 778w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.14.04-300x56.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.14.04-768x143.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>The default MON Policy setting is, as displayed, allowing only RFC-1918 subnets to be routed back to on-premise gateway :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"514\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.22.52.png\" alt=\"\" class=\"wp-image-694\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.22.52.png 800w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.22.52-300x193.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.22.52-768x493.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><figcaption>Only private subnet traffic is forwarded to the on-premise router. Internet egress is sent to the SDDC Compute Gateway.<\/figcaption><\/figure>\n\n\n\n<p>To change the default policy routing to route default egress traffic to on-premise, you simply have to  add a 0.0.0.0\/0 route in the list as allowed.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"786\" height=\"51\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.51.png\" alt=\"\" class=\"wp-image-695\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.51.png 786w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.51-300x19.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.51-768x50.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p>The default route is now displayed in the policy Routes setting:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"788\" height=\"167\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.57.png\" alt=\"\" class=\"wp-image-696\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.57.png 788w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.57-300x64.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.25.57-768x163.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p>Default route means that Internet traffic will flow over the Interconnect from SDDC to the on-premise gateway.<\/p>\n\n\n\n<p>Let&#8217;s check it by launching a traceroute again from my VM in the SDDC:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"860\" height=\"283\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.30.13.png\" alt=\"\" class=\"wp-image-698\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.30.13.png 860w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.30.13-300x99.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-19.30.13-768x253.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>It shows now that the traffic is sent to my on-premise default gateway (192.168.2.1). <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\">Conclusion<\/h2>\n\n\n\n<p>When you have MON enabled with the default <em>route policy <\/em>settings and you are advertising 0.0.0.0\/0 into the SDDC, HCX ignore this and still send traffic out of the IGW.<\/p>\n\n\n\n<p>Whenever you advertised the default route to the SDDC through BGP, you <strong>must <\/strong>change the default Policy to avoid egress traffic to be sent to the Tier-0 router, otherwise you will experience asymmetric routing.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently have had a question from a customer asking me how the default route is managed into HCX when Mobility Optimized Network is enabled. Basically when extending multiple VLANS from on-premise to VMware Cloud on AWS by leveraging HCX, you may still want to send egress traffic to an on-premise security device in order &hellip; <a href=\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;HCX MON Policy routes&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-684","post","type-post","status-publish","format-standard","hentry","category-hcx"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>HCX MON Policy routes - vminded.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HCX MON Policy routes - vminded.com\" \/>\n<meta property=\"og:description\" content=\"I recently have had a question from a customer asking me how the default route is managed into HCX when Mobility Optimized Network is enabled. Basically when extending multiple VLANS from on-premise to VMware Cloud on AWS by leveraging HCX, you may still want to send egress traffic to an on-premise security device in order &hellip; Continue reading &quot;HCX MON Policy routes&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\" \/>\n<meta property=\"og:site_name\" content=\"vminded.com\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-24T18:10:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-25T18:00:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png\" \/>\n<meta name=\"author\" content=\"Christophe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christophe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\"},\"author\":{\"name\":\"Christophe\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"headline\":\"HCX MON Policy routes\",\"datePublished\":\"2021-06-24T18:10:50+00:00\",\"dateModified\":\"2021-08-25T18:00:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\"},\"wordCount\":719,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png\",\"articleSection\":[\"HCX\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\",\"url\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\",\"name\":\"HCX MON Policy routes - vminded.com\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png\",\"datePublished\":\"2021-06-24T18:10:50+00:00\",\"dateModified\":\"2021-08-25T18:00:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage\",\"url\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png\",\"contentUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png\",\"width\":850,\"height\":214},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/vminded.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HCX MON Policy routes\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vminded.com\/#website\",\"url\":\"https:\/\/vminded.com\/\",\"name\":\"vminded.com\",\"description\":\"feed your mind with virtual thoughts\",\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/vminded.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\",\"name\":\"Christophe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"caption\":\"Christophe\"},\"logo\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/vminded.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HCX MON Policy routes - vminded.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/","og_locale":"en_US","og_type":"article","og_title":"HCX MON Policy routes - vminded.com","og_description":"I recently have had a question from a customer asking me how the default route is managed into HCX when Mobility Optimized Network is enabled. Basically when extending multiple VLANS from on-premise to VMware Cloud on AWS by leveraging HCX, you may still want to send egress traffic to an on-premise security device in order &hellip; Continue reading \"HCX MON Policy routes\"","og_url":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/","og_site_name":"vminded.com","article_published_time":"2021-06-24T18:10:50+00:00","article_modified_time":"2021-08-25T18:00:21+00:00","og_image":[{"url":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png","type":"","width":"","height":""}],"author":"Christophe","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christophe","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#article","isPartOf":{"@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/"},"author":{"name":"Christophe","@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"headline":"HCX MON Policy routes","datePublished":"2021-06-24T18:10:50+00:00","dateModified":"2021-08-25T18:00:21+00:00","mainEntityOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/"},"wordCount":719,"commentCount":0,"publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png","articleSection":["HCX"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/","url":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/","name":"HCX MON Policy routes - vminded.com","isPartOf":{"@id":"https:\/\/vminded.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png","datePublished":"2021-06-24T18:10:50+00:00","dateModified":"2021-08-25T18:00:21+00:00","breadcrumb":{"@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#primaryimage","url":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png","contentUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/06\/Screenshot-2021-06-24-at-18.12.55.png","width":850,"height":214},{"@type":"BreadcrumbList","@id":"https:\/\/vminded.com\/index.php\/2021\/06\/24\/hcx-mon-policy-routes\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vminded.com\/"},{"@type":"ListItem","position":2,"name":"HCX MON Policy routes"}]},{"@type":"WebSite","@id":"https:\/\/vminded.com\/#website","url":"https:\/\/vminded.com\/","name":"vminded.com","description":"feed your mind with virtual thoughts","publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vminded.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a","name":"Christophe","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","caption":"Christophe"},"logo":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/vminded.com"]}]}},"_links":{"self":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/comments?post=684"}],"version-history":[{"count":12,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/684\/revisions"}],"predecessor-version":[{"id":714,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/684\/revisions\/714"}],"wp:attachment":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/media?parent=684"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/categories?post=684"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/tags?post=684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}