NSGroups can be configured to contain a combination of IP sets, MAC sets, logical ports, logical switches, and other NSGroups. You can specify NSGroups with Logical Switches, Logical ports and VMs as sources and destinations, and in the Applied To field of a firewall rule. NSGroups with IPset and MACSet will be ignored in a distributed firewall Applied To field.
NSX Cloud Note: If using
NSX Cloud, see
How to use NSX-T Data Center Features with the Public Cloud for a list of auto-generated logical entities, supported features, and configurations required for
NSX Cloud.
An NSGroup has the following characteristics:
- An NSGroup has direct members and effective members. Effective members include members that you specify using membership criteria, as well as all the direct and effective members that belong to this NSGroup's members. For example, assuming NSGroup-1 has direct member LogicalSwitch-1. You add NSGroup-2 and specify NSGroup-1 and LogicalSwitch-2 as members. Now NSGroup-2 has direct members NSGroup-1 and LogicalSwitch-2, and an effective member, LogicalSwitch-1. Next, you add NSGroup-3 and specify NSGroup-2 as a member. NSGroup-3 now has direct member NSGroup-2 and effective members LogicalSwitch-1 and LogicalSwitch-2. From the main groups table, clicking on a group and selecting would show NSGroup-1, NSGroup-2, and NSGroup-3 because all three have LogicalSwitch-1 as a member, either directly or indirectly.
- An NSGroup can have a maximum of 500 direct members.
- The recommended limit for the number of effective members in an NSGroup is 5000. The NSX Manager check the NSGroups regarding the limit twice a day, at 7 AM and 7 PM. Exceeding this limit does not affect any functionality but might have a negative impact on performance.
- When the number of effective members for an NSGroup exceeds 80% of 5000, the warning message NSGroup xyz is about to exceed the maximum member limit. Total number in NSGroup is ... appears in the log file. When the number exceeds 5000, the warning message NSGroup xyz has reached the maximum numbers limit. Total number in NSGroup = ... appears.
- When the number of translated VIFs/IPs/MACs in an NSGroup exceeds 5000, the warning message Container xyz has reached the maximum IP/MAC/VIF translations limit. Current translations count in Container - IPs:..., MACs:..., VIFs:... appears in the log file.
- The maximum supported number of VMs is 10,000.
- You can create a maximum of 10,000 NSGroups.
For all the objects that you can add to an NSGroup as members, you can navigate to the screen for any of the objects and select
.Prerequisites
Verify that Manager mode is selected in the NSX Manager user interface. See NSX Manager. If you do not see the Policy and Manager mode buttons, see Configure User Interface Settings.