The import process has certain limitations. Some of them have workarounds.

  • The Manager to Policy importer cannot roll back completely once the distributed firewall sections and rules are imported in phase 2.

    Workaround: You must use the Backup and Restore feature in this case to restore the cluster to its original configuration in Manager.

  • In Policy mode, an NSX load balancer can support a maximum of 255 rules. If a cluster has an Ingress resource that has more than 255 rules, migrating the cluster from Manager mode to Policy mode will fail.

    Workaround: Create LoadBalancer CRDs to distribute the rules across multiple NSX load balancers.