Newly published DNAT or firewall rules fail to sync to specific Edge or Host Transport Nodes. Inbound connections from external clients to the public NAT address fail to establish.
error: 335544539-short read.VMware NSX
The Transport Node certificate has expired, preventing the Management Plane Agent (MPA) from establishing a secure communication channel with the NSX Manager. This failure prevents the distribution of configuration updates, including new DNAT rules or firewall policies.
The resolution for this article is as per the article 345825
Manual intervention is required for any node originally deployed on 4.1.x/4.2.0.
For NSX versions from 4.1.0 through to 4.2.0 inclusive:
Note:
openssl x509 -enddate -noout -in /etc/vmware/nsx/host-cert.pem.Transport Node has an expired or expiring certificate but is still connected to NSX:
Transport Node certificate has expired and TN is in a disconnected state in NSX:
cat /dev/null > /etc/vmware/nsx/host-cert.pemcat /dev/null > /etc/vmware/nsx/host-privkey.pemGenerate a new self-signed TN certificate and key:
For NSX 4.1.2.5 and higher, restarting the nsx-proxy service creates the new cert-key pair:(Move to Step 4 post this):/etc/init.d/nsx-proxy restart
For NSX 4.1.x versions prior to 4.1.2.5:
cat /etc/vmware/nsx/openssl-proxy.cnf > /tmp/tmp-openssl-proxy.cnf echo "UID = $(grep -o '<uuid>[^<]*' /etc/vmware/nsx/host-cfg.xml | sed 's/<uuid>//')" >> /tmp/tmp-openssl-proxy.cnfecho -e "[ req_ext ]\nbasicConstraints = CA:FALSE\nextendedKeyUsage = clientAuth\nsubjectKeyIdentifier = hash\nauthorityKeyIdentifier = keyid,issuer" >> /tmp/tmp-openssl-proxy.cnfopenssl req -new -newkey rsa:2048 -days 3650 -nodes -x509 -keyout /etc/vmware/nsx/host-privkey.pem -out /etc/vmware/nsx/host-cert.pem -config /tmp/tmp-openssl-proxy.cnf -extensions req_extget certificate api thumbprintsu admin -c push host-certificate <Manager hostname-or-IP> username admin thumbprint <thumbprint from step 4>su admin -c sync-aph-certificates <Manager hostname-or-IP> username admin thumbprint <thumbprint from step 4>nsxcli -c push host-certificate <Manager hostname-or-IP> username admin thumbprint <thumbprint from step 4>nsxcli -c sync-aph-certificates <Manager hostname-or-IP> username admin thumbprint <thumbprint from step 4> Note: the get controllers command might show an old disconnected NSX manager. Running the above commands might result in the following error: % Push certificate failed: 'internal error'
In that case, run the get controllers command again and this time, it will show the right NSX manager IP.
6. In the NSX UI, navigate back to the host under System-->Fabric-->Hosts and resolve the alarm by selecting the host disconnected link.
7. If the Transport Node status still reflects an error, it is sometimes necessary to restart the nsx-proxy and nsx-opsagent on the Transport Node to restore this connection.
/etc/init.d/nsx-proxy restart/etc/init.d/nsx-opsagent-appliance restart/etc/init.d/nsx-proxy restart/etc/init.d/nsx-opsagent restart