[VMC] Gateway Firewall status in the Failed state
search cancel

[VMC] Gateway Firewall status in the Failed state

book

Article ID: 317506

calendar_today

Updated On:

Products

VMware Cloud on AWS

Issue/Introduction

  • Compute Gateway Firewall status in NSX will be in the Failed state:-
  • The North-South connectivity from/to the VMs behind the Compute Gateway router may be impacted.
  • Creating new firewall rules and updating existing firewall rules is not working. 
  • The SDDC is of version 1.22

Environment

VMware Cloud on AWS

Cause

Gradual memory leak in the NSX Firewall service affecting NSX 4.1.0 build in SDDC version 1.22

Resolution

  • This issue is permanently resolved in SDDC version 1.22v8 and above.
  • Workaround:
    • The current workaround is to perform an NSX Edge failover.
    • To have this workaround applied, open a Wolken case with VMware Cloud on AWS team (Get Support).
    • Note: NSX Edge Failover will briefly impact north-south traffic.