IPFIX Profile Remains on NSX Manager After Disabling DFW IPFIX in VCF Operations for Networks
search cancel

IPFIX Profile Remains on NSX Manager After Disabling DFW IPFIX in VCF Operations for Networks

book

Article ID: 444743

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

  • After disabling Distributed Firewall (DFW) IPFIX and Latency metric collection for an NSX Manager, within the VMware Aria Operations for Networks user interface, the vRNI-DFW-IPFIX_Collector_Profile or another vRNI-related collector profile is still present on the NSX managers.

  • The profile was not automatically created by VCF Operations for Networks but was created by a user in NSX Manager.

  • Prior to disabling, two entries may be observed displaying the same collector IP address,  first one will be  associated with a global profile and second another displaying a zero profile.

    • The entry with the reference to a 'global' profile was removed automatically after removing the NSX integration from VCF Operations for Networks. This entry cannot be deleted through the NSX Manager UI.

      Below screenshot shows how the profile created by AON appears in NSX Manager:



  • The profile that needs to be removed has no active dependencies and is not in use.

Environment

  • VCF Operations for Networks 6.13.0
  • VCF Operations for Networks 6.134.x

Cause

The new profile persists on NSX-T Managers because it did not use default settings. The one that is automatically created by VCF Operations for Networks gets removed automatically when the integration is removed from VCF Operations for Networks GUI, however, the operation does not clean up any additional profiles manually added to NSX Manager.
These manually created profiles must be removed when the data source is disabled or prepared for migration.

Resolution

  1. Log in to the VMware Aria Operations for Networks  User Interface.

  2. Verify that the Collector profile is not currently in use and has been removed from all active data sources.



  3. Confirm that no active dependencies exist for the collector profile.
    • Navigate to Plan & Troubleshoot > IPFIX > Firewall IPFIX Profiles.

    • Select any active DFW profiles and review the Collector Profiles section. Ensure the target collector profile (e.g., vRNI-DFW-IPFIX_Collector_Profile) is not selected or assigned to any profile.

  4. Disable the data source from the vRNI UI to halt active data collection prior to environment migration.



  5. Log in to the NSX Manager client  to manually delete the stale Collector Profile entries if they are no longer required.