Login to NSX Manager via VIDM redirects back to local login page and can take 10-20 seconds to login
search cancel

Login to NSX Manager via VIDM redirects back to local login page and can take 10-20 seconds to login

book

Article ID: 450983

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

When attempting to log in to the VMware NSX Manager UI using VMware Identity Manager (vIDM), you may observe the following:

  • Clicking "Sign in with vIDM" redirects the browser back to the standard NSX local login page instead of the NSX dashboard.
  • It is necessary to click the "Sign in with vIDM" link multiple times to successfully authenticate.
  • There is a significant delay (10-20 seconds) before the login process completes.

Environment

  • VMware NSX 4.x
  • VMware Identity Manager (vIDM) / Workspace ONE Access

Cause

This issue occurs due to a time synchronization mismatch (clock drift) between the NSX Manager, the vIDM appliance, and other identity sources (such as Active Directory). Authentication tokens used in the SAML/OAuth2 handshake have strict Time To Live (TTL) windows. If the system clocks are not aligned, the token may be rejected as invalid or "not yet valid," forcing the UI to redirect back to the local login prompt.

Resolution

To resolve this issue, ensure all components are synchronized to the same authoritative time source.

  1. Log in to the vIDM Appliance Configurator at https://<vidm-fqdn>:8443/cfg/.
  2. Navigate to Time Synchronization.
  3. Select the NTP radio button and enter the FQDN or IP addresses of the NTP server.
  4. Click Save.
  5. Log in to the NSX Manager UI and configure NTP via the Node Profile, see Configure a Node Profile.

Additional Information

For detailed requirements, see Time Synchronization between NSX Manager, vIDM, and Related Components.

Subscribe to a Broadcom knowledge article by article or product for updates on time-synchronization best practices.