Unable to add a virtual machine to a vSphere Distributed Switch 5.5 portgroup with traffic filtering rules applied
search cancel

Unable to add a virtual machine to a vSphere Distributed Switch 5.5 portgroup with traffic filtering rules applied

book

Article ID: 301996

calendar_today

Updated On:

Products

VMware

Issue/Introduction

Symptoms:
When you configure traffic filtering rules on a vSphere 5.5 Distributed Switch (VDS), you experience these symptoms:
  • When you connect a virtual machine to a distributed switch portgroup with traffic filtering rules applied, you see an error in the vSphere Client or the vSphere Web Client:

    Cannot create DVPort portnumber of VDS switchname on the host hostname
    A general system error occurred.


  • When you attempt to modify an existing traffic filtering rule on a port group, you see this error:

    Cannot complete a vSphere Distributed Switch operation for one or more host members.
    vDS operation failed on host hostname, Received SOAP response fault from [<cs p:00007f1a7c030450, >TCP:hostname:443>]: invokeHostTransactionCall
    Received SOAP response fault from [<cs p:1f3b04a8, TCP:localhost:8307>]: invokeHostTransactionCall
    A general system error occurred: got (vmodl.fault.SystemError) exception


  • In the hostd.log file, located at /var/log/, on the target ESXi host contains entries similar to:

    YYYY-MM-DD TIME 21.859Z [FF90D5B0 error 'Default' opID=577f035c-5f user=vpxuser] AdapterServer caught unexpected exception: Not a valid netmask



Cause

This issue occurs when you define a traffic filtering rule with these conditions:
  1. A source IP qualifier defined as a subnet including a network address and subnet mask prefix.
  2. A destination IP qualifier defined as a single IP address.
Note: Creation of the rule may complete successfully but subsequent attempts to add or modify rules, or to connect virtual machines to the configured port group may fail.

Resolution

This issue is resolved in ESXi 5.5 Update 2, available at VMware Downloads.

For more information, see the Resolved Issues in the VMware ESXi 5.5 Update 2 Release Notes.

To work around the issue, avoid using the traffic filtering rules with a subnet defined as the source. Other traffic filtering rules without a subnet defined as the source functions as normal.


Additional Information

To be alerted when this document is updated, click the Subscribe to Article link in the Actions box

For related information, see the Traffic Filtering and Marking Policy in the VMware vSphere Networking 5.5 Guide.

トラフィック フィルタリング ルールが適用された vSphere Distributed Switch 5.5 ポートグループに仮想マシンを追加できない