Live Patch scan script '01_nsxhost_scan.py' returned a warning: Getting a list of addrsets on global filter FAILED. Please check if nsxt-vsip is running, it is possible that no addrsets are configuredDuring the ESX 9.x upgrade pre-check phase, the 01_nsxhost_scan.py script first checks to see if the the nsxt-vsip (DFW) module is loaded. This module is loaded by default in VCF 9.x, regardless of whether the DFW is in use. When the script sees that the module is loaded, it then attempts to query DFW rules on the host. When the DFW is not enabled, there will be no rules present on the host and an error is returned, resulting in the pre-check warning.
This warning can be ignored and the in-place upgrade can be allowed to proceed.
If the DFW is enabled and this same warning is generated, an investigation of the health of the nsx-vsip module on the affected ESX hosts will be needed. Open a support case with Broadcom Support. For more information, see Creating and managing Broadcom support cases.
If the upgrade pre-check produces the same message but it is an Error and not a Warning, the most likely scenario is that there are layer-7 firewall rules applied to the host. In this scenario, the upgrade must be changed to a maintenance mode based upgrade or the specific firewall rules must be disabled.
See In-Place Upgrades for more information on the limitations of in-place upgrades in VCF 9.1