No Flows are receiving flows from data sources in VCF Operations for Networks
search cancel

No Flows are receiving flows from data sources in VCF Operations for Networks

book

Article ID: 423172

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

  • No flows for Application VMs where DVPG is on NSX Manager which has been added as datasource in VCF Operations for Networks.  

    Refer to below screenshot where vCenter and NSX datasources do not show flow numbers.



  • flows query when on UI does not shows any flows at all.
    Refer to below screenshot:



  • NSX added datasource in VCF Operations for Networks shows last flows collected 59 days ago.
    Refer to below screenshot:




  • Executing tcpdump command on collector shows no incoming packets from the hosts on port 2055
    ubuntu@aria-networks-collector:~$ sudo tcpdump -i eth0 port 2055
    ^X

    Note: ^X means the command execution is cancelled using ctrl +X as no output of incoming packets are seen.

 

 




Environment

  • VCF Operations for Networks 6.13.0
  • VCF Operations for Networks 6.14.0
  • VCF Operations for Networks 6.14.1

Cause

  1. IPFIX Netflow packets getting dropped in between by a firewall (NSX, Virtual or Physical). Ensure that the Netflow packets destined for UDP port 2055 on VMware Aria Operations for Networks collector IP is allowed by any firewall that may be present in the route between ESXi Host and the VMware Aria Operations for Networks Collector.
     
  2. The ESXi host has ceased to send IPFIX Netflow packets. The ESXi host backs off sending the Netflow packets after some time if UDP port 2055 is not reachable which happens due to firewall dropping the packets.

    Resolution

    To resolve this issue perform below with help of your datacenter Network administrator

    1. Ensure UDP port 2055 is enabled.

    2. Make sure there is no firewall or DFW blocking the traffic between the hosts and the collector on port 2055.

    3. If Firewall is blocking then, unblock it or create a exception.

    4. Once firewall block is fixed, execute tcpdump command on collector shows no incoming packets from the hosts on port 2055

    ubuntu@aria-networks-collector:~$ sudo tcpdump -i eth0 port 2055

    5. Default polling interval is 10 minutes, it should take a couple of polling intervals (approx. 20-30 minutes) for flows to appear on the Aria Operations for Networks UI.

     

    Additional Information

    See available public facing documentation IPFIX FAQ for more details.