Connection between host <UUID> and NSX Controller is UNKNOWN. Response: Client is responding to heartbeats.
YYYY-MM-DDT14:48:09Z nsxaVim: [2102356]: INFO Entered update lockdown exception to [add] user [nsx-user]^@YYYY-MM-DDT14:48:09Z nsxaVim: [2102356]: INFO Adding user nsx-user in lockdown exception list^@YYYY-MM-DDT14:48:09Z nsxaVim: [2102356]: WARNING User <user name> does not exist retrying updating exception list^@
VMware NSX
VMware NSX-T Datacenter
If the HostClient or vCenter Lockdown exception list includes Active Directory users which are subsequently removed from the AD domain server, the ESXi host will not automatically remove the user from the list of lockdown exceptions.
This "stale" Lockdown mode exception user can cause the nsxaApp service to go down on the ESXi host, which in turn will prevent the Host from successfully being configured as NSX transport node.
/var/run/log/nsxdavim.log
/etc/init.d/nsx-opsagent restartNote: The user may also exist in the HostClient UI, please review and remove the mentioned user from the HostClient UI if it exists.
Please refer to the KB Article - Unable to prepare ESXi hosts for NSX due to existing stale Lockdown Mode exception user(s) for similar issue.