Hello to all.
I usually use the Service Composer to manage my the DFW rules.
But for testing some components, it was necessary to create a separate section in the DFW partition.
After I found the section through the filter, I found that there is no possibility to add or delete rules!
If you do not use a filter, then everything is fine, you can add and remove rules.
Is this so specially made?
I am afraid to imagine what would happen if all my rules were created in sections.
They could not be managed. Manual search for the desired section is not very convenient, especially when there are many.
Hi,
It's the first time I have seen this issue, but it strikes me as, by design. Because you are using the sections function in the DFW, the software might not know which section you want to add the new rule too. I wouldn't be surprised if this is "fixed" in a later version of the code. What version are you using?
Try adding a new rule to a different section using the same UDP-8888 service. Filter by service 8888 and filter again, you should see 2 rules in 2 different sections (hopefully). Does that then allow you to add/delete rules?
I've just checked on my version of 6.4.0 and I have the same issue.
My version 6.4.2.9643711
A very strange situation. Managing rules with a large number of sections is not very convenient.
It can be a little messy, but it's the same issue when you have 100's of FW rules regardless of sections.
Try minimizing all of the sections and only opening the one you need to edit. I find that helps. Continue to use the filter to find rules you need to check or edit.
Unfortunately what you've described has been around since the very beginning of NSX (i.e. 6.0 days), you just learn to workaround/live with it.