Unable to vMotion VMs via vCenter on a HP Synergy Cluster using Guest Introspection
search cancel

Unable to vMotion VMs via vCenter on a HP Synergy Cluster using Guest Introspection

book

Article ID: 442288

calendar_today

Updated On:

Products

VMware vCenter Server VMware NSX VMware vSphere ESXi

Issue/Introduction

You have added or moved a blade in a HP Synergy cluster, and are unable to vMotion VMs onto the host. Guest Introspection has been disabled, but still shows deployed in NSX, possibly with a red X, and the DSM (Deep Security Manager) doesn't exist any more.

Environment

NSX w/ security only Deployment for Guest instrospection.

vSphere

Cause

  • This is the expected behavior for Guest Introspection - vMotion of user VMs to an unprotected host should be blocked. Hosts can be configured to be protected by TrendMicro.
  • Since the profiile still shows Introspection, the new host by default is expecting the SVM to be deployed to the host. Since the DSM is gone or not functioning, the DSM won't be deployed, so new VMs will be rejected from the host until the issue is rectified.

Resolution

In the above scenario, the only option is to remove the Security only deployment. IF the DSM still exists the proper way is to:

  1. On the Deep Security Manager console, go to Computers.
  2. Right-click the vCenter connector and choose Properties.
  3. Go to the NSX Manager tab.
  4. Click the Remove NSX Manager button, and then click Apply and OK.
  5. Uninstall the Deep Security Service on the NSX environment:
    1. Go to the NSX Manager.
    2. Navigate to System > Service Deployments.
    3. Under the Deployment tab, select the partner service deployment, click the three dots/settings icon, and select Delete.
    4. Wait for the uninstall to finish
  6. On the Deep Security Manager console, go back to vCenter Properties and add the NSX Manager address under the NSX Manager tab.
  7. Under the General tab, click Synchronize Now.
  8. Once the synchronization is complete, deploy the Deep Security Virtual Appliance again.

If the DSM is already gone, and your goal is to just get the system accepting vms, then just do step 5 above.

 

Additional Information

Trend Micro Success "VM needs to be rebooted..." shows while the deployment of Deep Security Service on NSX failed"