SSP: TNs not sending flows after Backup and Restore operation
book
Article ID: 392331
calendar_today
Updated On:
Products
VMware vDefend FirewallVMware vDefend Firewall with Advanced Threat Prevention
Issue/Introduction
This issue is intermittent. Backup and restore operation can sometimes cause a transaction leak on NSX, resulting in unexpected number of profiles to be pushed down to the host.
Environment
SSP 5.0 with NSX 4.2.1
Cause
Transport nodes begin sending flows once the PACE HOST CONFIG profile is applied to them.
When backup and restore operation is performed on SSP, a transaction leak on the onboarded NSX manager causes multiple PACE HOST CONFIG profiles to be applied to the host. Corfu, the DB on NSX stores it's transactions in local storage and not heap. So if a thread leaks a transaction, regardless of what code path is takes next, those paths are going to produce unintended results.
The exporter on the host is not designed to handle multiple profiles, which causes it to become unstable and stop sending flows.
Resolution
Toggle data collection ( turn it off and turn it back on) from the UI, on clusters or standalone hosts that are not sending flows.