IDPS Signature Download is still not working after replacing an expired Advanced Threat Prevention license with a new license
search cancel

IDPS Signature Download is still not working after replacing an expired Advanced Threat Prevention license with a new license

book

Article ID: 319127

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

  • A new Advanced Threat Prevention license was applied after a previous ATP license expired. 
  • Not able to Update Signatures. Latest update not visible in NSX UI.
  • Manually triggering the Signature download via below API fails:

    POST /policy/api/v1/infra/settings/firewall/security/intrusion-services/signatures?action=update_signatures

  • The following exception is observed in /var/log/proton/nsxapi.log on NSX-T Managers:

    2022-09-27T07:40:10.738Z INFO task-scheduler-8 PolicyIDSUtils 9568 POLICY [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] IDS - Got Exception while authenticating with cloud client
    2022-09-27T07:40:10.738Z INFO task-scheduler-8 PolicyIDSUtils 9568 POLICY [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] IDS - Got errorCode 100003 while authenticating with cloud client, trying to re-register-with retry_auth_failure_once value true
    2022-09-27T07:40:10.738Z ERROR task-scheduler-8 PolicyIDSUtils 9568 POLICY [nsx@6876 comp="nsx-manager" errorCode="PM523683" level="ERROR" subcomp="manager"] IDS - Received Null or Blank access token

    Note: The above logs are examples. Timestamp and other parameters may vary.

Environment

VMware NSX-T Data Center 3.2.0.x or 3.2.1.x

Cause

In certain conditions (for example, after replacing an expired ATP license) authentication for registering with NSX-T cloud using the new license is not triggered.

Resolution

This issue is resolved in VMware NSX-T Data Center 3.2.2

Workaround:
Offline download procedure of  signatures can be followed as a workaround until upgrading to 3.2.2:
Offline Downloading and Uploading NSX Intrusion Detection Signatures

Additional Information

Impact/Risks:
Not able to fetch & update latest Signatures for IDPS automatically