Excessive number of login attempts through vIDM lock the admin account
book
Article ID: 399844
calendar_today
Updated On:
Products
VMware NSXVMware vDefend FirewallVMware vDefend Firewall with Advanced Threat Prevention
Issue/Introduction
There are continuous login attempts of the local user "admin" in vIDM every 5 minutes.
The logins are unsuccessful, and therefore, after a number of unsuccessful login failures, the account "admin" is locked in NSX.
Environment
VMware NSX 4.1.2.x
Cause
When onboarding the LM on any GM, the role is saved as "admin" and a password is provided for that role. This password expires after 90 days, as indicated in the UI. At that point, the user with the admin role is prompted to update the password. After the password is changed, the same API call is made from the GM. However, since the updated password is not reflected in the site details configured on the GM, the API call begins to fail due to invalid credentials. The issue occurs because the new password is not automatically updated in the enforcement point configuration on the GM.
Resolution
This issue is fixed in VMware NSX 9.0
Workaround:
Navigate to the site settings for the LM on the GM and update the password with the new one.
Once the updated password is saved, subsequent API calls will succeed.