When attempting to import a Local Manager (LM) site into an NSX Global Manager (GM), the import fails during the onboarding process. The GM UI displays the following error:
Unable to import due to these unsupported features: IDS/IPS Site Version Mapping not configured
A detailed inspection of the error log reveals:
Entity IDPS_SITE_VERSION_MAPPING_NOT_PRESENT at site <Site-Name> is not supported for configuration import on GM. Please delete entity IDPS_SITE_VERSION_MAPPING_NOT_PRESENT from the site <Site-Name> and try again.
vDefend Firewall.
vDefend Security Services Platform (SSP)
The configuration import fails due to a violation of the Security Services Platform (SSP) federation workflow:
The Local Manager is actively onboarded to an SSP instance. Per Broadcom documentation, a standalone NSX Local Manager must be offboarded from SSP before it can be imported and federated with a Global Manager. SSP locks IDPS and Malware Prevention configurations, leading GM to reject the import.
The LM contains lingering, active custom intrusion service policies (e.g., mps-mgmt-policy) or downloaded signature versions associated with Malware Prevention/IDPS that block the GM configuration import.
To successfully federate the Local Manager site with the Global Manager, complete the following steps:
Completely offboard the standalone Local Manager site from the SSP Instance.
Proceed with registering and importing the Local Manager configuration via the Global Manager UI.
Once the LM is successfully federated and synced with the Global Manager, re-onboard the Local Manager back onto the SSP Instance.
Reference Documentation: Onboard NSX Manager - Security Services Platform