VM IP still matching with older dynamic group(Tag based) even after the tag has been changed.
search cancel

VM IP still matching with older dynamic group(Tag based) even after the tag has been changed.

book

Article ID: 382707

calendar_today

Updated On:

Products

VMware vDefend Firewall

Issue/Introduction

** VM was part of the dynamic group (tag-based), and this VM was migrated to another dynamic group (tag-based) 'Shared-services'. However, the dynamic group that the VM was assigned to first holds the IP of the VM under the IP address. In the name field, the VM name however was not present.
** Due to this incorrect group matching the traffic will be impacted.

Environment

NSX-T 4.1.2

Cause

By default, the discovery methods ARP snooping and ND snooping operate in a mode called trust on first use (TOFU). In TOFU mode, when an address is discovered and added to the realized bindings list, that binding remains in the realized list forever. TOFU applies to the first 'n' unique <IP, MAC, VLAN> bindings discovered using ARP/ND snooping, where 'n' is the binding limit that you can configure. You can disable TOFU for ARP/ND snooping. The methods will then operate in trust on every use (TOEU) mode. In TOEU mode, when an address is discovered, it is added to the realized bindings list and when it is deleted or expired, it is removed from the realized bindings list. DHCP snooping and VM Tools always operate in TOEU mode

Resolution

Please try the below steps related to TOFU in the IP discovery profile to fix this issue.

Step 1. Create a new IP discovery profile and set Trust on First Use (TOFU) to off
Step 2. Ensure that the IP discovery profile applied has an ARP Binding Limit greater than or equal to the maximum number of IPs configured on a single port. Other settings can match the current IP discovery profile
Step 3. Apply the new IP discovery profile to the segment
Step 4. Wait for a time greater than the ARP ND Binding Limit Timeout (10 minutes in the default profile). This ensures stale entries are all aged out
Step 5. Turn TOFU back on