NSX Manager nodes missing from DFW System Exclusion List
book
Article ID: 375886
calendar_today
Updated On:
Products
VMware NSX
VMware vDefend Firewall
Issue/Introduction
- One of the NSX managers is not showing up in the DFW exclusion list.
- The NSX managers are deployed on NSX prepared host.
- Traffic to the NSX manager may be blocked by the DFW rules.
- For instance : Manager node1: mgp01 is not seen in the system excluded VM's.

Environment
- VMware NSX 3.x
- VMware NSX 4.x
Cause
- NSX Manager nodes deployed via OVF/OVA template do not automatically receive the 'SystemVM_NSGroup' tag.
- This tag is required by the NSX-T Management Plane to automatically add the VM to the System Exclusion List.
- Only nodes deployed directly from the NSX-T UI are tagged automatically during the deployment workflow."
Resolution
- There is no resolution as it is a default behavior.
Workaround:
- Delete and redeploy the 1st NSX manager from NSX UI for that to be show up in the exclusion list.
- Add the tag "SystemVM_NSGroup" manually to the NSX manager that is manually deployed.
Feedback
thumb_up
Yes
thumb_down
No