SCRX service may not be running after upgrading NSX from 9.0.1 to 9.1.1
search cancel

SCRX service may not be running after upgrading NSX from 9.0.1 to 9.1.1

book

Article ID: 452660

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

After upgrading NSX from version 9.0.1 to 9.1.1, the SCRX service might not be running on one or more affected hosts.

The SCRX module enables the L7 firewall and IDPS (Intrusion Detection and Prevention System) services, so these services can be impacted when SCRX is not running. In addition, the "Security Services Health Degraded" alarm may be raised in NSX.

This issue occurs very rarely during the upgrade.

Symptoms:

- The "Security Services Health Degraded" alarm is seen in NSX after upgrading from 9.0.1 to 9.1.1.
- Traffic that requires L7 classification before being permitted may not be handled correctly.
- Traffic subject to the IDPS service with an oversubscription policy of "drop" may be impacted.

Environment

 NSX Transformers 9.1.1

Cause

The SCRX service uses the config store service on the ESXi host to manage its persistent configuration.

During an upgrade, there is a rare race condition where the SCRX service starts before the config store service is ready. The existing SCRX startup implementation does not handle this condition gracefully and fails to start as a result.

Resolution

This is a known issue in NSX 9.1.1 and this issue is resolved in the upcoming NSX version.