Configure NSX Manager IP Exclusion to Prevent Account Lockout
search cancel

Configure NSX Manager IP Exclusion to Prevent Account Lockout

book

Article ID: 452048

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

This article provides instructions for configuring an IP exclusion list in VMware NSX Manager to prevent service accounts or automation appliances from being locked out due to repeated authentication failures.

Environment

VMware NSX Manager

Cause

NSX Manager authentication policies may trigger account lockouts after a specific number of failed login attempts. When automation appliances, such as VMware Aria Automation, attempt to communicate with NSX Manager with outdated or misconfigured credentials, the account becomes locked. Excluding the appliance IP address from the NSX Manager lockout policy prevents this lockout.

Resolution

Perform the following steps to configure the IP exclusion list in the NSX Manager:

  1. Log in to the NSX Manager UI using an account with administrator privileges.
  2. Navigate to System > Configuration > Profiles.
  3. Locate the Authentication Policy settings.
  4. Select the option to edit the IP Exclusion List.
  5. Add the IP address or CIDR range of the VMware Aria Automation appliance (or other relevant management appliances) to the list.
  6. Click Save to apply the configuration.
  7. Verify that the changes have propagated by monitoring the NSX audit logs for authentication attempts originating from the excluded IP addresses.

For command-line configuration requirements in restricted environments, refer to the Prevent Password Lockout on Local Manager Nodes

Additional Information

  • If the IP exclusion list does not resolve the lockout, ensure that the credentials utilized by the automation appliance are synchronized with the NSX Manager.
  • For details on managing support cases, refer to Creating and Managing Broadcom