Tier-1 Gateway Firewall rules have status In Progress or Unknown
book
Article ID: 324214
calendar_today
Updated On:
Products
VMware NSX Networking
Issue/Introduction
Symptoms:
NSX-T Data Center 3.1.x
Tier-1 Gateway Firewall rules have a status of "In Progress" or "Unknown"
The Gateway has no Edge cluster associated with it
Gateway Firewall has a blue banner
"No Service Router is associated with the selected Gateway. You need to associate an Edge Cluster to the Gateway."
Environment
VMware NSX-T Data Center VMware NSX-T Data Center 3.x
Cause
A Gateway Firewall will only be functional when that Gateway is associated with an Edge cluster. When a Gateway has no Edge cluster, the Gateway Firewall rules may show as In Progress or Unknown. There is no functional impact.
Resolution
This is a known behaviour of NSX-T Data Center 3.1.x.
Workaround: This status can be ignored as the Gateway Firewall is not functional without an Edge cluster.
To remove the In Progress/Unknown status, the Gateway's Firewall can be disabled Security -> Gateway Firewall -> Select Gateway from dropdown menu -> Actions -> General Settings