SSP App Discovery Reversion and Cleanup Script
search cancel

SSP App Discovery Reversion and Cleanup Script

book

Article ID: 413877

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention VMware vDefend Firewall

Issue/Introduction

Customers who have published policies and inventory assets generated through Segmentation Planning on SSP may want to undo these publications. Simply discarding the analysis through SSP will not revert the publications made to NSX.


We provide 2 scripts:
1) A script that identifies the groups, policies, rules, and tags published through an existing Segmentation Planning analysis and provides the option to revert them,
2) A script that identifies all groups that have been published through Segmentation Planning, and deletes them on NSX, as well as removes all hierarchy tags from their effective VMs.

 

Environment

The scripts work for SSP 5.1 and 5.1.1 . They are not applicable to other versions of SSP.

Cause

If publications are made to NSX through Segmentation Planning, they will remain on NSX even if the "Discard & Restart" button is used within Segmentation Planning. Publications that remain on NSX can include:

  • Hierarchy groups, such as Applications, Application tiers, and Environments.
  • Policies and Rules.
  • Tags that have been added to assets.
  • Tags that have been removed from assets.

Resolution

Please Contact Broadcom Support team to run scripts.

Attachments

cleanup-segmentation-objects.py get_app
app-discovery-reversion-script.zip get_app