After upgrading NSX from 3.2.x to 4.2.x, NSX Manager service (Proton) become unstable.
NSX Managers may enter a degraded or down state, impacting access to the NSX UI.
Proton logs show repeated JVM restarts with errors similar to:
com.vmware.nsx.management.common.exceptions.InvalidArgumentException: Invalid group with IPSet/MACAddress in ExclusionList ionList path=[/infra/domains/default/groups/<groupID>]Logs findings:
2024-10-07T18:39:50.257Z INFO WrapperStartStopAppMain ApplicationContextManager 227639 - [nsx@6876 comp="nsx-manager" level="INFO" starting NSX management plane application context.
STATUS | wrapper | 2024/10/07 18:39:51| JVM received a signal SIGKILL (9).
STATUS | wrapper | 2024/10/07 18:28:31 | Launching a JVM...
INFO | jvm 784 | 2024/10/07 18:33:30 | com.vmware.nsx.management.common.exceptions.InvalidArgumentException: Invalid group with IPSet/MACAddress in ExclusionList path=[/infra/domains/default/groups/<GroupID>]
API query reveals groups referenced in the exclusion list (e.g., VCenter, infra_vcenter) contain IP addresses.
The exclusion list contains groups with IP and MAC members, which are not supported.
Proton service fail to process these entries, causing repeated service failures and manager instability.
Remove IP or MAC addresses from groups configured in the exclusion list.
Once invalid members are removed, Proton service stabilizes and NSX Manager becomes operational.
Refer to ANS KB for more details: NSX Exclusion list modification fails due to invalid group with Ipset/MACAddress in FW Exclusion List (Error code:514051)