SSP Recommendation Behavior with Global Manager (GM) Groups in Federated NSX Environments
search cancel

SSP Recommendation Behavior with Global Manager (GM) Groups in Federated NSX Environments

book

Article ID: 436116

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

In a federated NSX environment, SSP may display Global Manager (GM)-created groups in inventory and Security Explorer. However, these groups are not fully supported for use in policy recommendations. This can lead to inconsistencies where GM groups are visible but cannot be selected or reused during recommendation workflows.


Attempting to:
Run recommendation using GM groups results in Errors like:

“Group … is not supported by recommendation”

Environment

NSX Federated environment (GM + LM) with SSP 5.x deployed on LM.

Cause

GM groups are:

  1. Displayed for visibility purposes only
  2. Not supported as input context for recommendation engine


Recommendation engine is designed to work with:
LM (Local) groups only

Resolution

Use LM-based groups

  • Create equivalent groups on Local Manager
  • Use these for recommendations

 

Avoid using:

  • GM groups directly in recommendation workflows