Data Collection Failed in VCF Operations for Networks via Blocked UDP 2055
search cancel

Data Collection Failed in VCF Operations for Networks via Blocked UDP 2055

book

Article ID: 442084

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

  • In VCF Operations for Networks, the UI displays a failure for a specific Collector node with the exact error message: "Data collection failed due to an error. Please wait for some time."

  • Network flow data fails to populate from the VMware Cloud (VMC) environment into the external Collector.

  • Packet captures using techniques described in KB 341568 - Packet capture on ESXi using the pktcap-uw tool show that TCP packets on port 443 are seen entering the VCF Operations for Networks Collector from ESXi hosts withing the VMC environment, yet UDP packets on port 2055 cannot be seen in the capture. 

  • NOTE:  VCF Operations for Networks was formerly named Aria Operations for Networks (AON), and prior to that was named vRealize Network Insight (vRNI).

Environment

VCF Operations for Networks

 

Cause

  • An intervening firewall is blocking IPFIX traffic.

  • The VCF Operations for Networks Collector is deployed outside the VMC environment, and a firewall rule is actively dropping UDP port 2055 packets originating from the VMC NSX Managers and ESXi management vmkernel interfaces before they can reach the Collector node.

Resolution

STEPS:

 

  1. Identify the firewall(s) governing egress traffic between the VMC environment and the external network hosting the VCF Operations for Networks Collector.

  2. Create or modify a firewall rule to explicitly allow traffic over UDP port 2055.

  3. Define the Source in the firewall rule to include the IP addresses of the VMC NSX Managers and the ESXi host Management vmkernel interfaces.

  4. Define the Destination in the firewall rule as the IP address of the VCF Operations for Networks Collector.

  5. Apply the firewall rule and verify within the VCF Operations for Networks UI that data collection status transitions to successful.

 

Additional Information

  • For comprehensive port and protocol requirements, refer to the official documentation on Broadcom TechDocs.