Symptoms
After converging an existing NSX4.x to a VCF9.x environment and performing an inventory synchronization, you may observe the following:
VMware NSX 4.x / 9.x
VMware Cloud Foundation 9.x
VMware vDefend Firewall
This behavior is expected in VCF 9.x as part of the management of configuration drift between vCenter Server and SDDC Manager. During inventory synchronization, if a cluster is not configured for NSX, SDDC Manager applies a TNP to the cluster and installs NSX. Additionally, "NSX on DVPGs" is enabled. This results in the application of the default Segment Security Profile, which blocks DHCP offer packets from a DHCP server.
This behavior is described in the following document.
Remediate VCF Domain Configuration Drift
To prevent service disruption during the VCF converge and synchronization process, consider the following options:
If the issue has already occurred:
Refer to the following document for information regarding NSX on DVPGs.
Activate NSX on Distributed Virtual Port Groups
Refer to KB437286 for the issue where the default Segment Security Profile affects DHCP.
Virtual Machines Not Receiving DHCP Offers Due to NSX Segment Security Profile