TLS 1.1 removal for default lb monitors during upgrade.
search cancel

TLS 1.1 removal for default lb monitors during upgrade.

book

Article ID: 427384

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Policy load balancer monitors without ssl profiles trigger precheck warnings during upgrade.
    Error message:
    Found data inconsistencies: There are unsupported SSL cipher suites or protocols found in LB objects. They are not in compliance with OpenSSL 3.0 starting from NSX version 4.2. Please make sure to take actions according to https://knowledge.broadcom.com/external/article?articleNumber=368005. Otherwise, LB traffic will be broken



  • In NSX 3.2.x, the default-https-lb-monitor does not have an SSL profile configured in the Policy API, so the manager automatically assigns it TLS 1.1 and TLS 1.2 by default.

 

Environment

VMware NSX

Cause

VMware NSX 4.x versions officially deprecate SSLV3 and TLS 1.1, hence a warning is raised during NSX upgrade precheck.

Resolution

  • Please make sure the load balancer pool members support TLS 1.2 and Openssl 3 ciphers. 
  • Proceed with upgrade to trigger automatic protocol migration.

Additional Information

Reference Broadcom KB 368005 for detailed migration steps.
Observed no manual intervention requirement for default-https-lb-monitor.