Active Directory security group stuck in 'In Progress' status in NSX Manager interface after being deleted
search cancel

Active Directory security group stuck in 'In Progress' status in NSX Manager interface after being deleted

book

Article ID: 373019

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Groups were created during NSX-V to NSX-T migration. The migration had completed, but the groups were not removed. 
  • Groups were deleted in the NSX GUI under Inventory > Groups after removing tags and any VM resources attached to the groups. 
  • The group is stuck in "In Progress" status and the group entries become grayed/greyed out, as demonstrated in the following screenshot.
  • NSX Manager reboots do not clear this state.  
  • Similar log entries can be found in syslog from the NSX manager:
2024-11-04T06:46:34.015Z  INFO providerTaskExecutor-88 PolicyRealizedStateServiceImpl 5096 POLICY [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] There still exists /infra/realized-state/enforcement-points/default/ip-sets/ip-sets-nsxt/DOMAIN-ipset-default-<v_temporary Group name>-<UUID> for intent /infra/domains/default/groups/<v_temporary Group name>. 

Environment

VMware NSX 4.1 and NSX-T 3.x

Cause

This is caused by stale entries of objects in group definition and realization table.

Resolution

If this issue is encountered, please open a case with Broadcom Global Support and attach the following files.

Please gather support bundles from the 3 NSX Managers and run the following commands to collect the database tables from a root user SSH session on an NSX Manager node: 

# /opt/vmware/bin/corfu_tool_runner.py -o showTable -n nsx -t GenericPolicyRealizedResource > /tmp/GenericPolicyRealizedResource.txt

# curl -k -X GET -H "Content-Type: application/json" -u 'admin:<password>' https://127.0.0.1/policy/api/v1/infra/domains/default/groups > /tmp/allGroups.txt

Additional Information