Multiple Firewall Rule IDs appear for a single flow in VCF Operations for Networks
search cancel

Multiple Firewall Rule IDs appear for a single flow in VCF Operations for Networks

book

Article ID: 403918

calendar_today

Updated On:

Products

VCF Operations for Networks VMware NSX

Issue/Introduction

  • A flow that previously hit one rule (e.g., R1) now shows hits for both the old rule and a new rule (e.g., R2).
  • The user sees the wrong rule name or rule ID for an active flow.
  • Multiple firewall rule IDs persist for the same flow for several hours.

Environment

VCF Operations for Networks

VMware NSX

Cause

This is expected behavior. When a firewall rule changes, VCF Operations for Networks does not immediately remove the association with the old rule. There is a default time window of 6 hours before the old rule metadata is purged and the flow record is updated exclusively with the new rule ID.

In environments using NSX-T Federation, multiple rules may also appear if rules are applied by both the Global Manager and a Local Manager.

Resolution

No technical action is required as the system is behaving as designed.

  1. Verify if the firewall rule was changed within the last 6 hours. Flows take maximum of 6 hours and may show both the rules. 
  2. Monitor the flow for 6 hours to allow the old rule ID to be removed from the AON database. 
    • And if this happens multiple times (e.g. R1->R2->R3), user will see multiple FW rules for a single flow. 
  3. If the duplicate rules persist beyond 6 hours,  ensure there is no overlapping rule application from a Global and Local Manager in a federated setup.