Dynamic security groups in NSX-T may retain outdated IP addresses for virtual machines, including Avi Service Engines, after an IP change. This issue occurs when the IP Discovery Segment Profile is configured with "Trust on First Use" (TOFU) enabled, preventing the system from automatically updating the realized IP bindings.
VMware vDefend Firewall.
By default, ARP and ND snooping operate in "Trust on First Use" (TOFU) mode. In this mode, NSX learns the first IP address assigned to a port and stores it permanently in the IpDiscoveryPersistedBinding table. This entry does not automatically age out or update when the IP changes, leading to stale entries in dynamic security groups.
Resolution: To resolve this issue, configure the affected segment to use "Trust on Every Use" (TOEU) mode to allow stale bindings to age out.
Create a Custom IP Discovery Profile:
Apply the Profile:
Wait for Aging:
IpDiscoveryPersistedBinding table.Verification: