3
2. Verify that correct VXLAN-related configurations exist on the leaf switch.
ï‚¡ If the leaf switch does not have correct VXLAN or VSI configurations, check the
configurations on the IMC Orchestrator controller or manually modify the configurations on
the leaf switch.
ï‚¡ If correct VXLAN and VSI tunnel configurations exist but forwarding still fails, go to step 3.
3. Verify that the correct VXLAN tunnel configuration exists on the leaf switch.
ï‚¡ In an EVPN network, the tunnel configuration is automatically generated by the hardware
switch based on the received EVPN BGP type-3 routes. If no tunnel-related configuration
exists, go to step 5 to troubleshoot the establishment of EVPN BGP neighbors.
ï‚¡ If the tunnel-related configuration has been generated, go to step 4.
4. Verify that the source and destination VTEP IP addresses used to establish the VXLAN tunnel
between leaf switches can communicate with each other normally.
ï‚¡ If the VTEP IP addresses are unreachable, go to step 5 to check the establishment of EVPN
BGP neighbors.
ï‚¡ If the VTEP IP addresses are reachable, go to step 6.
5. Check the EVPN BGP neighbor state between the leaf switch and the spine BGP route reflector.
If the neighbor state is abnormal, check the BGP configuration and the underlay links and
routes. If the neighbor state is normal, check the loopback interface configuration of the leaf
switch. After the VTEP IP addresses are reachable, go to step 6.
6. Check whether the forwarding mode of the leaf switch is local proxy ARP or ARP flood
suppression, which can be confirmed by using CLI on the switch. In the case of ARP flood
suppression, go to step 7. In the case of non-ARP flood suppression, go to step 9.
7. Verify that the MAC address entry for the faulty VM is established on the leaf switch. In ARP
flood suppression mode, the leaf switch needs to query the MAC address table to forward Layer
2 traffic. If no matching MAC address entry exists, verify that the corresponding AC interface
configuration exists, and that the MAC address is not aged. After confirming that the MAC
address entry exists, go to step 8.
8. Verify that the ARP suppression entry of the faulty VM is established on the leaf switch. When
the leaf switch replies to the ARP request on behalf of the VM, it queries the ARP suppression
table. If no matching entry exists, verify that the ARP suppression configuration and the AC
interface configuration exist on the switch and the IMC Orchestrator controller. After the ARP
suppression entry exists, go to step 11.
9. Verify that the ARP entry for the faulty VM is established on the leaf switch. When the leaf
switch replies to the ARP request on behalf of the VM, it queries the ARP table. If no matching
entry exists, verify that the AC interface configuration exists and that the ARP entry is not aged
on the leaf switch. After confirming that the ARP entry exists, go to step 10.
10. Verify that the host routing entry of the faulty VM is established on the leaf switch. In the local
proxy ARP mode, the leaf switch needs to query the host routing table to forward Layer 2 traffic.
If no matching table entry exists, verify that the VSI, VPN instance, L3VNI and other related
configurations on the switch are correct, and that a correct tunnel is mapped to the VSI. After
confirming that the host routing entry of the VM exists, go to step 11.
11. On the IMC Orchestrator controller, check security policy configuration for the two vPorts that
need to communicate. If the vPorts are configured with a security policy, make sure the security
policy permits the source and destination addresses of the vPorts, or remove the security policy
configuration. If the vPorts are not configured with a security policy, or after confirming that the
security policy permits the vPorts' traffic, go to step 12.
12. Examine other devices (network adapters of servers or network devices) that the traffic passes
through along the forwarding path. Locate where the traffic is lost, and sort through the possible
causes of packet loss on the intermediate links.
13. If the issue persists, contact Technical Support for help.