Unable to import Local Manager to Global Manager: IDS/IPS Site Version Mapping not configured
search cancel

Unable to import Local Manager to Global Manager: IDS/IPS Site Version Mapping not configured

book

Article ID: 451175

calendar_today

Updated On:

Products

VMware vDefend Firewall

Issue/Introduction

When attempting to import a Local Manager (LM) site into an NSX Global Manager (GM), the import fails during the onboarding process. The GM UI displays the following error:

Unable to import due to these unsupported features: IDS/IPS Site Version Mapping not configured

A detailed inspection of the error log reveals:

Entity IDPS_SITE_VERSION_MAPPING_NOT_PRESENT at site <Site-Name> is not supported for configuration import on GM. Please delete entity IDPS_SITE_VERSION_MAPPING_NOT_PRESENT from the site <Site-Name> and try again.

Environment

vDefend Firewall.

vDefend Security Services Platform (SSP)

Cause

The configuration import fails due to a violation of the Security Services Platform (SSP) federation workflow:

  1. The Local Manager is actively onboarded to an SSP instance. Per Broadcom documentation, a standalone NSX Local Manager must be offboarded from SSP before it can be imported and federated with a Global Manager. SSP locks IDPS and Malware Prevention configurations, leading GM to reject the import.

  2. The LM contains lingering, active custom intrusion service policies (e.g., mps-mgmt-policy) or downloaded signature versions associated with Malware Prevention/IDPS that block the GM configuration import.

Resolution

To successfully federate the Local Manager site with the Global Manager, complete the following steps:

  1. Completely offboard the standalone Local Manager site from the SSP Instance.

  2. Proceed with registering and importing the Local Manager configuration via the Global Manager UI.

  3. Once the LM is successfully federated and synced with the Global Manager, re-onboard the Local Manager back onto the SSP Instance.

Additional Information