Unable to View Related DFW Rules in NSX Application Platform(NAPP) - Plan & Troubleshoot page
search cancel

Unable to View Related DFW Rules in NSX Application Platform(NAPP) - Plan & Troubleshoot page

book

Article ID: 393000

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Log in to the NSX Manager using administrator credentials.

Navigate to Plan & Troubleshoot > Discover, then select Computes.

Right-click on any compute object and choose Related Firewall Rules. The page fails to load and eventually times out.

This issue occurs when attempting to view Related Distributed Firewall (DFW) Rules for a compute object in the NSX Application Platform (NAPP) UI. As a result, the firewall rules are not displayed.

Environment

All NAPP Environments

Cause

This behavior occurs when the environment contains Distributed Firewall rules that fall under unsupported policy categories.

Specifically, categories with a CATEGORY_VHC_* prefix (such as CATEGORY_VHC_APPLICATION, CATEGORY_VHC_INFRASTRUCTURE) are not recognized by the NAPP UI in versions up to 4.2.x.

These VHC-prefixed categories are typically introduced through other NSX projects or configurations and are not part of the standard set of categories supported by the visualization framework in NAPP.

When the UI encounters these unsupported categories while rendering the Related DFW Rules view, it results in a timeout or an error.

Resolution

This issue is resolved in the Security Services Platform (SSP) version 5.0 and later, where category mappings are handled more gracefully to support such configurations.

Recommended Actions:

  • Upgrade to SSP 5.0 or later, where unsupported categories from NSX are internally mapped to supported equivalents in the SSP visualization layer.