In an NSX environment, Aria Operations for Networks is reporting “high packet drops / more than 5%” warnings for NSX-T Logical Switch/Ports after applying DFW rules.
search cancel

In an NSX environment, Aria Operations for Networks is reporting “high packet drops / more than 5%” warnings for NSX-T Logical Switch/Ports after applying DFW rules.

book

Article ID: 322557

calendar_today

Updated On:

Products

VMware NSX VMware NSX VMware vDefend Firewall

Issue/Introduction

The following Warning Events may be present on Aria Operations for Networks (formerly vRealize Network Insight, vRNI)

  • NSX-T Logical Port Received Packets are getting dropped
  • Received packets are getting dropped on the NSX-T Logical Port and associated entities might get affected
  • NSX-T Logical Port Transmitted Packets are getting dropped.
  • Transmitted packets are getting dropped on the NSX-T Logical Port and associated entities might get affected

Environment

VMware NSX-T Data Center
VMware NSX

Cause

The DVS port statistics are cumulative, whereas the IOChain statistics are not. This means that while DVS stats continuously accumulate packet drops over time, IOChain stats reflect real-time drops without historical tracking.
As a result, there is no direct way to determine historical drop trends from IOChain stats alone.

Resolution

This issue has been resolved in the following versions:

  • VMware NSX 3.2.4

  • VMware NSX 4.1.2

  • VMware NSX 4.2.0

  • VMware Aria Operations for Networks 6.12

  • ESXi 8.0 Update 3e

During a review of code changes across various vSphere builds, it was identified that earlier versions did not include pktsFaulted in drop calculations, leading to discrepancies in the reported drop statistics.

This should be corrected in vSphere latest patch, ensuring accurate drop metrics in vRealize Network Insight (vRNI).

Workaround:

Aria Operations for Networks System Events can be disabled/suppressed.
Note: If there is a real condition that is causing dropped packets, you will not be alerted.

  1. In Aria Operations for Networks, go to Settings -> Events -> System Events
  2. Disable the following Events
  3. NSX-T Logical Port Received Packets are getting dropped.
  4. NSX-T Logical Port Transmitted Packets are getting dropped.