Failed to Publish DFW rules with Multiple Transport Node, Status 'UNKNOWN'
search cancel

Failed to Publish DFW rules with Multiple Transport Node, Status 'UNKNOWN'

book

Article ID: 449876

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Administrators may encounter an issue where Distributed Firewall (DFW) rules fail to publish to specific transport nodes.
  • NSX Manager UI, the realization status for these nodes is displayed as 'UNKNOWN'.

    Error Message Example:
    Returning current realization status 'Status = 'UNKNOWN', Message = 'Unable to collect status for [X] transport nodes.' 'Transport node is not connected to CCP. [Controller <Controller UUID>: This CCP is not the master of this TN.]

  • Despite the 'UNKNOWN' status in the NSX Manager, the affected ESXi hosts may appear healthy locally within the fabric.

Environment

VMware NSX

Cause

This issue occurs due to a service failure synchronization issue on one of the NSX Manager nodes in the cluster. Where services on an individual NSX Manager become degraded, it leads to an unstable cluster state and prevents CCP/DFW realization status from updating properly.

Resolution

To resolve this issue, the services on the faulty NSX Manager node must be resolved.

  • Identify the problematic node: Validate the status of internal services (Corfu, storage) across all NSX Manager nodes. For detailed diagnostic steps and log analysis, refer to Corfu status is not in UP state.

  • Verify isolation: 
  1. Confirm that the other two NSX Manager nodes are in a healthy state and maintaining cluster quorum.

  2. Power off the unhealthy NSX Manager node.

  3. Verify that the transport node realization status reverts to 'SUCCESS' and DFW rules publish as expected.

 

Additional Information

If the above steps also did not resolve the issue , open a support case with  Broadcom support: [For more information, see Creating and managing Broadcom support cases.]