When enabling/disabling the logging for the NAT, Firewall and VPN no change is made in NSX-T
book
Article ID: 382832
calendar_today
Updated On:
Products
VMware Cloud Director
Issue/Introduction
A Tenant Organization Admin user not able to toggle (enable or disable) Logging in the NAT, VPN, or Firewall rules under Data Centers > Networking > Edges > Edge gateway > Services
When modifying the Logging to Enable or Disable, no errors appear, the task succeeds in VMware Cloud Director (VCD) and no change is made in NSX-T and value remains unchanged.
However, a provider Organization Administrator user is able to modify the option without issues.
Environment
VMware Cloud Director 10.x
Cause
This is a known issue impacting Cloud Director 10.5.x UI. This issue has been resolved in 10.6.x
in 10.6.x, users will now see the error: " Cannot configure system logging, missing right: Organization vDC Gateway: Configure System Logging"
Resolution
The user will need the permission: "Configure System Logging" in order to update the logging option. ensure this is pushed from the default rights bundle as shown below:
To publish relevant rights and roles to org admin for the tenant, follow steps below :
Login to VCD provider
Go to Administration -> Right bundles -> Default set of tenant rights
Add the right "Configure System Logging" under Networking > Edge Gateway > Manage and publish
Go to Administration -> Global roles -> Organization Administrator
Enable the right "Configure System Logging" and publish
Refresh or re-login to the tenant portal as org admin user