IPFix profile configured but consistent traffic flow for DFW not seen in VCF Operations for Networks
search cancel

IPFix profile configured but consistent traffic flow for DFW not seen in VCF Operations for Networks

book

Article ID: 414888

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

Despite having an IPFix profile, we do not see consistent traffic flow for workloads with associated distributed firewall rules (DFW) in NSX.

Flows are not displaying for some workloads. Some flow entities appear to be working correctly.

 

You may see for some workloads when running the query in VCF Operations for Networks:

flow where Source VM = '<source IP address>' and Destination VM = '<destination IP address>'

The following result (example):

Search for Flow over time range Oct 17, 09:08 - Oct 17, 11:08 didn't return any results

Environment

VCF Operations for Networks 6.13
VCF Operations for Networks 6.14
VCF Operations for Networks 6.14.1

Cause

There is no traffic between <source IP address> and <destination IP address> for VCF Operations for Networks to display.

 

Resolution

Verify traffic is flowing with a tool like NSX Traceroute.

If it does not show any traffic between <source IP address> and <destination IP address>,  then Aria Operations for Networks is displaying the expected result as there is no traffic to display.

Resolve issue in the environment so that traffic is passing between <source IP address> and <destination IP address>.

Once traffic exists, Aria Operations for Networks should receive the flows and display them via the query.