This is a known issue affecting VMware NSX-T Data Center 2.5.1 and later versions and is fixed in VMware NSX-T Data Center 3.1.0.
Workaround:
To work around this issue, follow the deletion order in reverse of the order of creation and also check every deletion is successful before going to the next step.
Deletion Steps
East-West Network Security - Chaining Third-party Services
Undeploy a Service for East-West Traffic Introspection
After partners deploy services and test redirection policies, as an administrator, if you need to undeploy service instance you need to follow a particular order.
Procedure
- From your browser, log in with admin privileges to an NSX Manager at <https://<NSXMGR_IP>.
- Verify the NSX Manager is in Policy mode.
- Select Security > East West Security > Network Introspection (E-W) > EW Redirection Policy.
- Click the | vertical ellipsis on the Section and click Delete Policy.
- Click Publish.
- Select System > Service Deployments > Deployment > EW Service.
- Click the | vertical ellipsis on the Service and click Delete.
- Click the DELETE button in the delete popup that appears next.
- Select Security > Settings > Network Introspection Settings > Service Chain > EW Service Chain.
- Click the | vertical ellipsis on the Service Chain and click Delete.
- Navigate to Security > East West Security > Network Introspection > Service Profiles > EW Service Profile.
- Click the | vertical ellipsis on the Service Profile and click Delete.
- Click Security > Settings > Network Introspection Settings > Service Segment > EW Service Segment.
- Click the | vertical ellipsis on the Service Segment and click Delete.
North-South Network Security - Inserting Third-party Service
Undeploy a Service for North-South Traffic Introspection
After partners deploys services and test redirection policies, as an administrator, if you need to undeploy service instance you need to follow a particular order.
Procedure
- From your browser, log in with admin privileges to an NSX Manager at <https://NSXMGR_IP>.
- Verify the NSX Manager is in Policy mode.
- Select Security > East West Security > Network Introspection (N-S) > NS Redirection Policy.
- Click the | vertical ellipsis on the Section and click Delete Policy.
- Click Publish.
- Select System > Service Deployments > Deployment > NS Service.
- Click the | vertical ellipsis on the Service and click Delete.
- Click the DELETE button in the delete popup that appears next.