This topic provides information on understanding and troubleshooting VMware NSX 6.x Distributed Firewall (DFW).
Problem
- Publishing Distributed Firewall rules fails.
- Updating Distributed Firewall rules fails.
Cause
Validate that each troubleshooting step below is true for your environment. Each step provides instructions or a link to a document to eliminate possible causes and take corrective action as necessary. The steps are ordered in the most appropriate sequence to isolate the issue and identify the proper resolution. After each step, re-attempt to update/publish the Distributed Firewall rules.
Solution
Solution
-
Ensure that VMware Tools is running on the virtual machines if firewall rules do not use IP addresses. For more information, see https://kb.vmware.com/kb/2084048.
VMware NSX 6.2.0 introduced the option to discover the virtual machine IP address using DHCP snooping or ARP snooping. These new discovery mechanisms enable NSX to enforce IP address-based security rules on virtual machines that do not have VMware Tools installed. For more information, see the NSX 6.2.0 Release Notes.
DFW is activated as soon as the host preparation process is completed. If a virtual machine needs no DFW service at all, it can be added in the exclusion list functionality (by default, NSX Manager, NSX Controllers and Edge Services Gateways are automatically excluded from DFW function). There is a possibility that the vCenter Server access gets blocked after creating a Deny All rule in DFW. For more information, see https://kb.vmware.com/kb/2079620.
-
When troubleshooting VMware NSX 6.x Distributed Firewall (DFW) with VMware Technical Support, these are required:
- Output of the command show dfw host hostID summarize-dvfilter on each of the ESXi host on the cluster.
- Distributed Firewall Configuration from the Networking and Security > Firewall > General tab and click Export Configuration. This exports the Distributed Firewall configuration to an XML format.
- NSX Manager logs. For more information, see https://kb.vmware.com/kb/2074678.
- vCenter Server logs. For more information, see https://kb.vmware.com/kb/1011641.