Disabling vApp Firewall on VMware Cloud Director doesn't disable it on NSX
search cancel

Disabling vApp Firewall on VMware Cloud Director doesn't disable it on NSX

book

Article ID: 412854

calendar_today

Updated On:

Products

VMware Cloud Director VMware NSX

Issue/Introduction

  • When attempting to disable the firewall, VMware Cloud Director (VCD) successfully completes the operation, but the NSX Firewall remains enabled.
  • Disabling vApp firewall on VCD does not have an effect on NSX.
  • The issue affects routed networks.
  • If the firewall is enabled from VCD. Rules can be added/deleted and applied.
  • If the firewall is disabled in VCD. Rules can be added/deleted but are not applied.
  • This could also result in the following error being reported in NSX: "The number of T0/T1 Service routers ... has exceeded the maximum threshold of 98%".

Environment

  • VMware Cloud Director 10.6.1.1
  • VMware NSX 4.2.2.1

Cause

Though the Gateway Firewall state is still shown as "ON" in NSX, the rules that are added/removed from it decides whether firewall is applied on traffic/not

Resolution

This is expected behavior. When the firewall is disabled in VCD, no rules are applied. Conversely, when it is enabled, rules take effect regardless of the toggle state in NSX.

This issue is resolved in VMware Cloud Director 10.6.1.2 as per the release notes.

For product download instructions, see Download Broadcom products and software.

Additional Information