WAF Configuration show Inactive in VMware Cloud Director UI
search cancel

WAF Configuration show Inactive in VMware Cloud Director UI

book

Article ID: 448959

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

  • In VMware Cloud Director, a tenant sees the WAF status listed as Inactive.
  • Active WAF events and traffic entries continue to appear in the Logs tab.
  • The backend Avi Load Balancer confirms that the WAF policy is active and functioning properly on the Virtual Service.

Environment

VMware Cloud Director 10.6.x

Cause

  • This issue occurs due to a naming mismatch of WAF policies between VCD and the Avi Load Balancer.
  • You can identify the expected WAF policy name in VCD (this can typically be seen in logs or by inspecting the object ID).

Resolution

Broadcom Engineering is aware of this issue and are actively working to resolve this in a future version of VMware Cloud Director (VCD).

Workaround Steps:
The issue was resolved by fully cleaning up the existing conflicting objects on the VMware Avi Load Balancer and VCD, then recreating them from scratch:

  1. Delete the existing WAF Policy from the Avi Controller.
  2. Delete the existing WAF Profile from the Avi Controller.
  3. Delete the Virtual Service from VCD.
  4. Recreate the Virtual Service in VCD using the same name, VIP and configuration.
  5. Activate the WAF policy on the newly created VS from VCD.
  6. After completing these steps, VCD successfully created a new WAF Policy without any naming conflict, and the WAF status transitioned to ACTIVE.

Note: This procedure involves deleting the Virtual Service and will cause a brief service interruption. It is recommended to perform these steps during a planned maintenance window. Ensure all VS configuration details (VIP, pool members, SSL profiles, policies) are documented and exported as backup before deletion.