NSX Manager nodes missing from DFW System Exclusion List
search cancel

NSX Manager nodes missing from DFW System Exclusion List

book

Article ID: 375886

calendar_today

Updated On:

Products

VMware NSX VMware vDefend Firewall

Issue/Introduction

 

  • One of the NSX managers is not showing up in the DFW exclusion list.
  • The NSX managers are deployed on NSX prepared host.
  • Traffic to the NSX manager may be blocked by the DFW rules.
  • For instance : Manager node1: mgp01 is not seen in the system excluded VM's.

Environment

  • VMware NSX 3.x
  • VMware NSX 4.x

Cause

  • NSX Manager nodes deployed via OVF/OVA template do not automatically receive the 'SystemVM_NSGroup' tag.
  • This tag is required by the NSX-T Management Plane to automatically add the VM to the System Exclusion List.
  • Only nodes deployed directly from the NSX-T UI are tagged automatically during the deployment workflow."

Resolution

  • There is no resolution as it is a default behavior.

Workaround:

  • Delete and redeploy the 1st NSX manager from NSX UI for that to be show up in the exclusion list.
  • Add the tag "SystemVM_NSGroup" manually to the NSX manager that is manually deployed.

Additional Information

Reference document link > Manage Firewall Exclusion List