Academy/VCAP — VCF Networking (3V0-25.25)/Stretched Segment Failover & vMotion across Sites
This lab targets VCF 9.0

Stretched Segment Failover & vMotion across Sites

VCF 9.0Intermediatevcap-advanced⏱ 150 min

Objectives

  • Create stretched segment, deploy VM at Site-A, vMotion to Site-B, verify IP/MAC preservation and DFW rules enforcement.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Advanced VCF 9.0 Networking (NSX & Advanced Routing)

Tasks

Task 1 Stretched Segment Failover & vMotion across Sites

Create stretched segment, deploy VM at Site-A, vMotion to Site-B, verify IP/MAC preservation and DFW rules enforcement.

Step 1

On Global Manager, create stretched segment: prod-segment (10.100.0.0/24), assigned to both Site-A and Site-B Tier-1 routers.

Step 2

Verify segment created at both Local Managers: List segments on site-a-manager and site-b-manager.

Step 3

Deploy VM (web-server) on Site-A; assign IP 10.100.0.10; verify traffic reaches Site-B (confirm Layer 2 connectivity).

Step 4
Configure DFW rule: allow web-server → db-server (at Site-B) on port 3306.
Step 5
Test connectivity Site-A → Site-B: ping db-server; mysql -u root db-server
Step 6

Initiate vMotion: Migrate web-server from Site-A ESXi cluster to Site-B ESXi cluster.

Step 7

Monitor vMotion progress: Track MAC address location; confirm no traffic loss during migration.

Step 8

Post-migration: Verify web-server still has IP 10.100.0.10 (no DHCP re-issue).

Step 9

Verify DFW rule still enforced (same rule ID, same source/dest, regardless of site).

Step 10

Failback: vMotion web-server back to Site-A; verify symmetric behavior.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

Stretched segment latency exceeding vMotion threshold
Fix: Stretched segments require <150ms RTT for vMotion. If inter-site latency exceeds this, vMotion fails with timeout. Measure actual RTT with ping -c 100 between TEPs at both sites. For vSAN stretched cluster on the same stretched segment, the requirement is stricter: <5ms RTT.
Not configuring preferred egress on stretched T1 gateway
Fix: Without preferred egress, VMs on a stretched segment may egress through the remote site's Edge — adding WAN latency to every north-south packet. Configure: set preferred site on T1 gateway so VMs egress locally.
MTU inconsistency across WAN link for GENEVE traffic
Fix: Stretched segments use GENEVE overlay across the WAN. If WAN link MTU < 9000 (or < 1600 for GENEVE + headers), packets fragment or drop. Verify WAN MTU supports GENEVE overhead. If WAN limits MTU to 1500, reduce overlay MTU on Edge transport nodes.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

Stretched networking is critical for multi-site VCF architectures. VCDX panelists test latency awareness, egress optimization, and failure domain understanding.

⚠ Known Pitfalls (from Community KB)

Stretching segments across WAN without verifying MTU support for GENEVE encapsulation.
Not configuring preferred egress — VMs hairpin through the remote site for north-south traffic.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.