Unable to change Gateway Firewall Security Policy state from Stateless to Stateful on Edge Gateways created by VMware Cloud Director
search cancel

Unable to change Gateway Firewall Security Policy state from Stateless to Stateful on Edge Gateways created by VMware Cloud Director

book

Article ID: 449814

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

  • An Edge Gateway is deployed via VMware Cloud Director (VCD) while the Edge Cluster's Stateful Firewall option is set to Inactive.
  • Firewall rules are added to the Edge Gateway in VCD.
  • In the NSX Manager UI, the Security Policy's Stateful parameter is displayed as No.
  • Attempting to change the Stateful setting to Yes in the NSX Manager UI and selecting APPLY then PUBLISH fails with the following error:
    Error: The SecurityPolicy state, once set, cannot be modified from Stateless to Stateful. (Error code: 500194)

Environment

VMware Cloud Director 10.6.1.x
VMware NSX 4.2.x

Resolution

This is by design. There is currently no procedure or workaround to modify the Stateful/Stateless property of an existing Edge Gateway.
To deploy an Edge Gateway with a Stateful Gateway Firewall, refer to Creating stateful firewall rule with Cloud Director UI.

Additional Information

Creating stateful firewall rule with Cloud Director UI
VMware Cloud Director から作成された Edge Gateway において、NSX 上で Gateway Firewall セキュリティ ポリシーの状態を Stateless から Stateful に変更できない