VMware NSX for vSphere 6.x Distributed Firewall (DFW) is non-functional on an ESXi host
search cancel

VMware NSX for vSphere 6.x Distributed Firewall (DFW) is non-functional on an ESXi host

book

Article ID: 341212

calendar_today

Updated On:

Products

VMware NSX Networking

Issue/Introduction

Symptoms:
  • Virtual machines migrated to an ESXi host are not firewalled and are accessible from systems that should be blocked.
  • The VXLAN and Logical Distributed Router services are also experiencing failures on the ESXi host.
  • Running the command esxcli software vib list | egrep "vxlan|vsip|switch-sec" fails to display any VIBs running.
  • In the /var/log/esxupdate.log file on the ESXi host, you see entries similar to:

    2015-04-13T08:43:49Z esxupdate: imageprofile: INFO: Adding VIB VMware_bootbank_esx-vxlan_5.5.0-0.0.2318233 to ImageProfile (Updated) ESXi-5.5-1331820-RollupISO-standard
    2015-04-13T08:43:49Z esxupdate: imageprofile: INFO: Adding VIB VMware_bootbank_esx-vsip_5.5.0-0.0.2318233 to ImageProfile (Updated) ESXi-5.5-1331820-RollupISO-standard
    2015-04-13T08:43:49Z esxupdate: imageprofile: INFO: Adding VIB VMware_bootbank_esx-dvfilter-switch-security_5.5.0-0.0.2318233 to ImageProfile (Updated) ESXi-5.5-1331820-RollupISO-standard
    2015-04-13T08:43:49Z esxupdate: HostImage: WARNING: Failed to acquire lock: ('/var/run/esximg.pid', 'Error locking lock file: [Errno 11] Resource temporarily unavailable')
    2015-04-13T08:43:49Z esxupdate: esxupdate: ERROR: LockingError: Another process is updating the ESX image. Please try again later.
    2015-04-13T08:43:49Z esxupdate: esxupdate: DEBUG: <<<

    Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.


Environment

VMware NSX for vSphere 6.0.x
VMware NSX for vSphere 6.1.x
VMware NSX for vSphere 6.2.x

Cause

This issue occurs if the esx-vxlan, esx-vsip and esx-dvfilter-switch-security VIBs did not install correctly on the affected ESXi host.

Resolution

To resolve this issue:
  1. Place the affected ESXi host on maintenance mode.
  2. Reboot the ESXi host.
  3. Move the ESXi host out of the NSX Prepared cluster.
  4. Move the ESXi host back into the NSX Prepared cluster.
  5. Verify the VIBs are correctly installed. For more information, see Troubleshooting vSphere ESX Agent Manager (EAM) with NSX (2122392).


Additional Information

Troubleshooting vSphere ESX Agent Manager (EAM) with NSX
VMware NSX for vSphere 6.x Distributed Firewall (DFW) 在 ESXi 主机上不起作用
VMware NSX for vSphere 6.x Distributed Firewall (DFW) が ESXi ホストで機能しない