Migrating vCloud Director Edge Gateway Firewall in NSX-V to NSX-T has warning on group "external"
search cancel

Migrating vCloud Director Edge Gateway Firewall in NSX-V to NSX-T has warning on group "external"

book

Article ID: 390507

calendar_today

Updated On:

Products

VMware vCloud Director 5.x VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention VMware NSX Data Center for vSphere

Issue/Introduction

vCloud Director, while integrated with NSX-V, created a group named "external" for the Edge Gateway firewall, which creates a warning when migrating to NSX-T by using the vCloud Director Migration Utility.

The group "external" was created by vCloud Director only when integrated with NSX-V.   The group was defined as the external vNics of the edge vm.   No such group exists when vCloud Director is integrated with NSX-T due to architectural differences, so there is no way for the vCloud Director Migration Utility to automatically migrate it.

Environment

VMware vCloud Director

vDefend Firewall

VMware vDefend Firewall with Advanced Threat Prevention

 

Cause

Architectural differences between NSX-V and NSX-T

Resolution

One solution is to create a group that uses the external IP's or networks and use that in your rule or just list those IP's or networks in the rules.