ESXi Host Profile shows non-compliant due to missing "dfwipfix0" firewall ruleset error "Ruleset dfwipfix0 not found"
search cancel

ESXi Host Profile shows non-compliant due to missing "dfwipfix0" firewall ruleset error "Ruleset dfwipfix0 not found"

book

Article ID: 444608

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

When checking Host Profile compliance for an ESXi host in a vSphere environment integrated with NSX, the host reports a status of "Not Compliant".

The compliance failure lists the following specific error:
 "Ruleset dfwipfix0 not found"

Environment

VMware vSphere ESXi
VMware NSX

Cause

This behavior is expected and by design.

The dfwipfix0 firewall ruleset is dynamically created on an ESXi host only when there is at least one active Virtual Machine running on that host that is connected to an NSX-T segment. If an ESXi host has no virtual machines running on it, or if its VMs are not attached to NSX-managed segments, the dfwipfix0 ruleset will not be instantiated in the ESXi firewall configuration.

Consequently, if the Host Profile was extracted from a host that had this active ruleset, any host without active NSX-segment VMs will fail compliance checks due to the "missing" rule.

Resolution

Because the dfwipfix0 firewall ruleset is dynamic and depends entirely on active VM workloads, it should not be used as a static factor for Host Profile compliance.

To resolve the non-compliance status, remove the firewall configuration requirement for this dynamic rule from the Host Profile:

  1. Log in to the vSphere Client.

  2. Navigate to Policies and Profiles > Host Profiles.

  3. Select the affected Host Profile and click Edit Host Profile.

  4. Expand the configuration tree to locate the Security/Firewall settings:

    • Security and Services > Firewall configuration > Ruleset.

  5. Locate the dfwipfix (or dfwipfix0) ruleset policy.

  6. Uncheck or disable the compliance checking factor for this specific ruleset so it is excluded from validation.

  7. Save the changes to the Host Profile and remediate/re-check compliance on your cluster.

Additional Information

Reference Article:
https://knowledge.broadcom.com/external/article/389634/nsx-dfw-ipfix-not-displaying-in-esxi-fir.html