VM port blocked state on NSX segment prevents connectivity
book
Article ID: 405110
calendar_today
Updated On:
Products
VMware NSX
Issue/Introduction
A virtual machine appears in a blocked state on an NSX segment port and is not visible in the NSX Manager segment ports view. The affected VM cannot establish network connectivity despite being configured identically to other functional VMs on the same segment. The VM shows as connected to the NSX segment in vCenter but does not appear in the NSX segment port listings.
Error messages may include:
Port showing as "blocked" status in ESXi diagnostics
VM not appearing in NSX Manager segment port view
Network connectivity failures from the affected VM
Steps to validate the issue:
Check ESXi host where the VM is running using net-dvs -l | grep -E "port |port.block|volatile.vlan|volatile.status"
Verify output shows "Port blocked by admin" status
Confirm VM is assigned to NSX segment in vCenter but missing from NSX Manager ports view
Validate other VMs on the same segment are functioning normally
Environment
VMware NSX-T Data Center 3.x
VMware NSX 4.x
VMware vSphere ESXi
VMware vCenter Server
Cause
The issue occurs when the VM network port is blocked at the VDS level on the ESXi host, combined with NSX Manager cluster health issues that prevent proper port state synchronization. Critical services on NSX Manager nodes may be in a down state, preventing the cluster from properly managing and displaying port states across the environment.
Resolution
Step 1: Identify the blocked port
SSH to the ESXi host where the affected VM is running