Count of workloads in Security Segmentation Report may be higher than expected.
search cancel

Count of workloads in Security Segmentation Report may be higher than expected.

book

Article ID: 390549

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

The count of workloads shown in the  Security Segmentation Report may be higher than the count of workloads the user expects. Each section in the Security Segmentation Report counts "Workloads" as addition of both NSX managed workloads and Internal IPs (IPs that fall under "Private IP Ranges" of the Security Services Platform).

Sample Screenshot of NSX Inventory where we see 777 Virtual Machines

 

 

Sample screenshot of POV report where workloads count is 2463

 

Environment

Security Services Platform 5.0 (SSP 5.0)

Cause

Count of workloads being higher than expected may happen in multiple scenarios, here are a few illustrative examples:

Workloads that fall under Private IP ranges defined in SSP and communicate with at least one NSX managed workload will be counted. 
If NSX managed workloads generated flows in the report duration, but were also deleted during the period for which the report was generated, then those deleted workloads will also be included in workload count.
There can be some instances where the NSX managed VMs may be counted twice (once as NSX managed VM and second as internal IP) during VM reboots. 

Resolution

The above mentioned details are for informational purposes. There is no specific resolution at this point in time