NSX Distributed Firewall Rules Not Applied to VMs
search cancel

NSX Distributed Firewall Rules Not Applied to VMs

book

Article ID: 451106

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention VMware vDefend Firewall

Issue/Introduction

  • In NSX / vDefend Firewall 9.0.x, Distributed Firewall (DFW) rules are not being applied to VMs, and traffic is hitting the default rule (ID 99999999) instead of the configured firewall rules. Even after creating new rules in the UI, the new rules are not pushed to the ESXi hosts and the traffic continues to match the default rule.
  • ESXi hosts show only default rule with ID 99999999 applied to the VMs
  • vDefend Distributed Firewall License is missing in the NSX Manager

Environment

 VMware NSX / vDefend Firewall 9.0.x

Cause

The necessary vDefend Distributed Firewall license is not applied to the NSX Manager. While other licenses (such as a VCF license) may be active, the specific vDefend Distributed Firewall license is required for DFW rules to be successfully pushed and enforced on the ESXi hosts once the grace period is over.

Resolution

Apply the vDefend Distributed Firewall License Key if it's missing:

  • Browse to the Broadcom Support Portal.
  • Locate the license key for vDefend Distributed Firewall. (See KB 430651)
  • Add this license key to the NSX Manager to trigger rule population and enforcement on the ESXi hosts.
  • Verify that the rules are now applied by checking the traceflow or ESXi host rules again.