Use Traceflow to inspect the path of a packet. Traceflow traces the transport node-level path of a packet. The trace packet traverses the segment overlay, but is not visible to interfaces attached to the segment. In other words, no packet is actually delivered to the test packet’s intended recipients.
For a VLAN-backed segment, enable In-band Network Telemetry (INT) by calling the PUT /api/v1/infra/ops-global-config
API.
Sample request:
URL:
PUT https://{{nsx-manager-ip}}/policy/api/v1/infra/ops-global-config
Body
{ "display_name": "ops-global-config", "in_band_network_telementry": { "dscp_value": 2, "indicator_type": "DSCP_VALUE" }, "path": "/infra/ops-global-config", "relative_path": "ops-global-config", "_revision": 0 }
INT cannot be configured if a traceflow request is already in progress. For more information about APIs for In-band Network Telemetry, see NSX. VLAN traceflow supports only TCP/UDP and ICMP packets.
VLAN tracing is not supported on Edge nodes. Attempting to inject a trace packet on an Edge node results in an API validation error. For a VLAN traceflow, if the injected trace packet traverses an Edge node, the resultant trace is incomplete and only observations on ESX nodes are displayed.
You can view the IPSec VPN specific observations when the packet is processed.