When the NSX Manager loses its license entitlement it triggers a phased degradation as per following,
- When NSX Manager is unable to obtain its entitlements from the vCenter server for a period of three consecutive days, then a warning banner appears in the NSX Manager UI.
- During this three-day period, all create, update, read & delete operations are allowed.
- If the issue is not rectified within three days, the NSX Manager appliances that are connected to the vCenter server will enter a grace period for a further 90 days. During this grace period, the warning banner continues to be displayed in the NSX Manager UI.
- If the license issue is not rectified within the grace period and the grace period expires, then NSX Manager is entitled to only those features that are supported by the default NSX for vShield Endpoint license.
- For features that are not supported by the default license, only read and deleted operations are allowed. All edit and create operations are blocked.
- Management Plane Impact:
- You cannot create new logical segments, deploy new Tier-0 or Tier-1 gateways, modify existing distributed firewall (DFW) rules, or add new edge transport nodes. All Create and Edit operations are blocked.
- You will be barred from applying new security licenses if the underlying base network entitlement is expired or invalid.
- Data Plane Impact:
- Existing network traffic, routing, and already-configured overlay/VLAN segments will continue to forward packets normally.
- The ESXi hosts retain the last known working state of your distributed firewall rules. Active network sessions will not drop.