HTTP 401 Unauthorized when accessing NSX UI in VCF environment
search cancel

HTTP 401 Unauthorized when accessing NSX UI in VCF environment

book

Article ID: 451242

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Accessing the NSX UI fails with an HTTP 401 Unauthorized error.
  • NSX Cluster VIP is unreachable.
  • SDDC Manager Password Management reports admin and audit accounts as Disconnected.
  • CLI command get cluster status returns: % An error occurred while getting the cluster status.
  • Disk utilization on /config and /var/log partitions is within normal limits.

Environment

  • VMware Cloud Foundation
  • VMware NSX

Cause

This issue is typically caused by an authentication or token synchronization failure between the reverse proxy and the management plane (proton). This state often follows management service degradation or stalled JDK thread execution, which prevents SDDC Manager from successfully authenticating against the NSX API, even when storage is not exhausted.

Resolution

Fixed in release VMware NSX 4.2.x  and higher. See Download Broadcom Products and Software  to download this release.

If the issue persists, perform a controlled rolling reboot of the NSX Manager nodes to restore local management services:

  1. Confirm storage utilization is normal using df -h.
  2. Reboot the NSX Manager nodes one at a time.
  3. Allow 40 minutes for management services to initialize fully.
  4. Verify the NSX Cluster VIP is reachable and log in to the NSX UI.

If the HTTP 401 error remains after the initialization window:

  • Log in via SSH/bash to inspect /var/log/proton/nsxapi.log and /var/log/corfu/corfu.log for active errors.
  • Attach the NSX support bundle via CLI: get support-bundle file ####.

To speak with a customer representative or a Support Engineer, Creating and managing Broadcom support cases.