MPS and NDR features display as DOWN or Degraded in SSP due to Proxy Authentication failure
search cancel

MPS and NDR features display as DOWN or Degraded in SSP due to Proxy Authentication failure

book

Article ID: 447843

calendar_today

Updated On:

Products

VMware vDefend Network Detection and Response VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

 

  • Status for Malware Prevention Service (MPS) and Network Detection and Response (NDR) features unexpectedly displays as DOWN.

  • The overall SSP platform operational status is reported as Degraded.

 

Environment

SSP 5.X

Cause

This issue occurs when an proxy server intercepts outbound traffic from the SSP cluster to required backend cloud infrastructure but rejects it due to an authentication policy restriction.

Even if the internal Kubernetes infrastructure and microservice pods are fully operational and healthy, the proxy drops external requests with an HTTP 407 error (Proxy Authentication Required), preventing the platform from validating its connection to cloud portals like nsx.lastline.com.

Resolution

Once the network/proxy team corrects the access rules, verify recovery via the following metrics:

  1. Re-test target accessibility from the SSP network manager UI; checks to nsx.lastline.com should now return a successful status.

  2. On the SSP UI, navigate to System → Server Configurations → Proxy Server and test the Internet Proxy  connectivity with test URL  as https://nsx.lastline.com  and confirm connectivity succeeded without any errors 
  3. Confirm that both MPS and NDR statuses have automatically refreshed and returned to a healthy, green UP operational state after few minutes .

if issue still persists , please contact Broadcom Support team