All Posts

Hi all, After i removed my 3th standby cell , i tried to re install it again , but : setup stuck on "Invoking setupvcd script." (screen in attachment) configure-vcd.log 2023-09-02 16:20:03 | co... See more...
Hi all, After i removed my 3th standby cell , i tried to re install it again , but : setup stuck on "Invoking setupvcd script." (screen in attachment) configure-vcd.log 2023-09-02 16:20:03 | configure-vcd.sh | Invoking setupvcd script. 2023-09-02 16:20:03 | setupvcd.sh | System ip0 is: 10.40.12.14 2023-09-02 19:39:51 | configure-vcd.sh | Appliance OS Phase has been Completed. 2023-09-02 19:39:51 | configure-vcd.sh | Starting Appliance Cloud Director Configuration Phase. 2023-09-02 19:39:51 | configure-vcd.sh | Invoking check-vcd-params script again. 2023-09-02 19:39:51 | check-vcd-params.sh | Checking ovf parameters needed for proper Cloud Director configuration ... 2023-09-02 19:39:52 | check-vcd-params.sh | All the required ovf parameters provided for the Cloud Director configuration phase 2023-09-02 19:39:52 | configure-vcd.sh | Invoking nfs-setup script. 2023-09-02 19:39:52 | nfs-setup.sh | Mounting NFS file share ... 2023-09-02 19:39:52 | nfs-setup.sh | Listing contents of transfer share directory total 44 drwxr-x--- 29 vcloud vcloud 0 Sep 2 19:36 . drwxr-x--- 4 vcloud vcloud 4096 Sep 2 19:36 .. drwxr-x--- 7 vcloud vcloud 0 May 6 2022 03ca24d5-2714-460e-9f5e-aeb322d06cc1 drwxr-x--- 7 vcloud vcloud 0 May 4 2022 0d11e4c3-b566-49d3-9154-db19b315c33a drwx------ 2 vcloud vcloud 0 Oct 26 2022 15231fda-dc3b-4e1d-be7d-2c9c108bfd3d drwxr-x--- 5 vcloud vcloud 0 Feb 21 2023 406a6801-cbe9-41a7-83d2-8d1322fece19 drwxr-x--- 2 vcloud vcloud 0 Mar 14 18:45 461a35fe-cd35-400d-97bc-b792cf65d63b drwxr-x--- 7 vcloud vcloud 0 May 4 2022 57c44928-5a22-40e4-84f6-752248c6ebed drwxr-x--- 2 vcloud vcloud 0 Nov 14 2022 5a3f0f31-1b87-4f9d-981a-52b52d5c47f2 drwxr-x--- 7 vcloud vcloud 0 May 4 2022 8c7f22e3-538e-325e-a163-0746d0bacf4b drwxr-x--- 7 vcloud vcloud 0 May 4 2022 a223f5ea-3e9a-4af3-83da-fc72e7a2e851 drwxr-x--- 2 vcloud vcloud 0 Nov 25 2021 b17bedf9-9027-4e87-b465-1f5ee22f2a66 drwxr-x--- 3 vcloud vcloud 0 Sep 2 16:30 appliance-nodes drwxr-x--- 2 vcloud vcloud 0 Apr 25 15:48 b1355b8e-c255-41b4-8a63-1e37718167b6 drwxr-x--- 6 vcloud vcloud 0 Sep 2 09:33 backups drwxr-x--- 7 vcloud vcloud 0 May 6 2022 bd5c1eca-2cf1-4ff7-9146-c360c58866f8 drwxr-x--- 3 vcloud vcloud 0 Sep 2 14:28 cells -rwxr-x--- 1 vcloud vcloud 13345 Feb 22 2021 certificates.ks drwxr-x--- 1 vcloud vcloud 0 Jul 6 16:07 gosc drwxr-x--- 2 root root 0 Sep 2 16:30 mig drwxrwx--- 25 vcloud vcloud 0 May 26 16:26 pgdb-backup -rwxr-x--- 1 vcloud vcloud 536 Sep 2 17:13 responses.properties -rwxr-x--- 1 vcloud vcloud 1874 Jul 26 10:58 user.consoleproxy.key -rwxr-x--- 1 vcloud vcloud 2223 Jul 26 10:58 user.consoleproxy.pem -rwxr-x--- 1 vcloud vcloud 1874 Jul 26 10:58 user.http.key -rwxr-x--- 1 vcloud vcloud 6485 Sep 2 17:07 user.http.pem 2023-09-02 19:39:52 | configure-vcd.sh | Invoking setupvcd script. 2023-09-02 19:39:53 | setupvcd.sh | System ip0 is: 10.40.12.14   Any idea how this issue can be resolved? vcd version 10.4.2
Hi Dejan, It would be helpful if you have mentioned what version of Cloud Director you are using and if your pvdc is backed by NSX-v or NSX-t. "As system administrator all DPGs are appeared in Prov... See more...
Hi Dejan, It would be helpful if you have mentioned what version of Cloud Director you are using and if your pvdc is backed by NSX-v or NSX-t. "As system administrator all DPGs are appeared in Provide VDC " DPGs shouldn't be listed in PVDC, i think you probably thought External networks. However, as Admin you should see vDS PortGroups in Resources\Infrastructure resources\Port Groups. "but when I want to add network in a OrgVDC with Import DPG only direct/isolated button can be chosen. " You are probably looking for "imported/ Distributed Virtual Port group option". This option should be available to you if you have NSX-T backed organization. I never been in situation to have only "direct/isolated options". It must be some non-standard configuration or a bug. If you previously had mentioned option available you can check with VMware support why you are missing it now. Additional, not sure why you want to import vDS Port Group to Org Network, I guess for some reason you need to have vDS PortGroup backed by physical VLAN. From my experience following options are available while adding Org Network: 1) In case your Organization vDC is backed by NSX-v (VXLAN), options during Org Network creation process are: Routed, Isolated and Direct. 2) In case your Organization vDC is backed by NSX-T (geneve), options during Org Network creation process are: Routed, Isolated, Direct and Imported [NSX-T logical switch and Distributed Virtual Port Group] Option that you are looking for is documented here: https://docs.vmware.com/en/VMware-Cloud-Director/10.5/VMware-Cloud-Director-Tenant-Guide/GUID-6FA096A4-9AE6-4F7E-AE65-C01D12ACA68D.html " User has administrator role on whole vcenter cluster which is used for registering vmware resurces in vCD". This is unusual. Usually User has only access to Cloud Director Org while admin has access to vCenter and Provider CD     
Issue solved with a workaround. Adding an IPv4 BGP Neighbor to the VRF Gateway solves the issue. In other words, the IPv4 BGP neighbor is not required for Tier 0 Gateways (IPv6 neighbor configured ... See more...
Issue solved with a workaround. Adding an IPv4 BGP Neighbor to the VRF Gateway solves the issue. In other words, the IPv4 BGP neighbor is not required for Tier 0 Gateways (IPv6 neighbor configured with IPv4 and IPv6 address families is OK) but it is required for VRF Tier0 Gateways. Seems like a bug somewhere in NSX-T!
We are experiencing a weird NAT issue while experimenting with Tier0 VRF Gateways (VCD 10.5, NSX 4.1.1). Environment 1: VM -> Routed Network -> Edge Gateway (with NAT configured) -> Shared T0 Gatewa... See more...
We are experiencing a weird NAT issue while experimenting with Tier0 VRF Gateways (VCD 10.5, NSX 4.1.1). Environment 1: VM -> Routed Network -> Edge Gateway (with NAT configured) -> Shared T0 Gateway -> Internet -> ping 8.8.8.8 works Environment 2: VM -> Routed Network - Edge Gateway (with NAT configured) -> Dedicated VRF T0 Gateway -> Internet -> ping 8.8.8.8 fails In other words, exact same setup with the only difference being the use of a dedicated VRF Gateway for the Provider Gateway used by the Edge. Now, it works end to end as adding an IPv6 prefix to that same VM (with the corresponding FW rules) allows that VM to ping 2001:4860:4860::8888 (no NAT used for IPv6). Anyone got NAT to work using VRF Gateways as T0? Note that we also advertise both IPv4 and IPv6 routes through an IPv6 neighbor for both environments Thanks, Marc.
Hi Sreec, Attached are the screenshots. It's a test environment as well. NSX is version 4.1.1.0.0.22224312 After doing a few things, the route redistribution in the VRF Gateway (SYSTEM-VCD-EDGE-SE... See more...
Hi Sreec, Attached are the screenshots. It's a test environment as well. NSX is version 4.1.1.0.0.22224312 After doing a few things, the route redistribution in the VRF Gateway (SYSTEM-VCD-EDGE-SERVICES-REDISTRIBUTION) changed to also advertise Connected Interface & Segments (Service Interface Subnet + Connected Segment). No idea what triggered that change (and how to control it) Thanks, Marc.    
It should work in 10.5 as well, i have a running config in my lab and it shows right output. Can you share the screenshot of org-vdc--->Networking->Edges->T1->Configuration->General . Also may i know... See more...
It should work in 10.5 as well, i have a running config in my lab and it shows right output. Can you share the screenshot of org-vdc--->Networking->Edges->T1->Configuration->General . Also may i know the version of NSX ? 
It is a dedicated VRF Gateway... But I have not found the option in Cloud Director 10.5 to make that change. I can of course do it directly in NSX. Thanks, Marc.
You can perform this if you have dedicated T0/VRF configured in the VDC. 
I think you will need to create an external network in the Provider VDC that is mapped to that Distributed Port Group. Then you will create an org VDC network that is direct connected to the External... See more...
I think you will need to create an external network in the Provider VDC that is mapped to that Distributed Port Group. Then you will create an org VDC network that is direct connected to the External Provider vDC network. When creating an org VDC make sure you choose direct. And select the external network
Hi, Not really. IP Prefix lists can be used to restrict what is advertised. But only NAT IPs are advertised to begin with (unless you manually change the VRF Gateway using the NSX-T UI/API which I w... See more...
Hi, Not really. IP Prefix lists can be used to restrict what is advertised. But only NAT IPs are advertised to begin with (unless you manually change the VRF Gateway using the NSX-T UI/API which I was hoping to avoid). Thanks, Marc.
Does somebody try to add an Organization VDC Network with an Imported Distributed Port Group(DPG)? As system administrator all DPGs are appeared in Provide VDC but when I want to add network in a Org... See more...
Does somebody try to add an Organization VDC Network with an Imported Distributed Port Group(DPG)? As system administrator all DPGs are appeared in Provide VDC but when I want to add network in a OrgVDC with Import DPG only direct/isolated button can be chosen. So we arent able to import DPG in a org VDC.   User has administrator role on whole vcenter cluster which is used for registering vmware resurces in vCD. Has somebody problem like this one and has some solution for it?    
Hi, It sounds like you asking for IP Prefix List in BGP: https://docs.vmware.com/en/VMware-Cloud-Director/10.5/VMware-Cloud-Director-Service-Provider-Admin-Guide/GUID-F2A3BC91-036A-4E29-A1C9-6EAB... See more...
Hi, It sounds like you asking for IP Prefix List in BGP: https://docs.vmware.com/en/VMware-Cloud-Director/10.5/VMware-Cloud-Director-Service-Provider-Admin-Guide/GUID-F2A3BC91-036A-4E29-A1C9-6EAB8602562E.html Have a nice day, Dawid
A Provider Gateway has been created using a Tier-0 VRF Gateway (Cloud Director 10.5) The Tier-0 VRF Gateway has eBGP configured and running with our core routers By default, only NAT-IPs from Tie... See more...
A Provider Gateway has been created using a Tier-0 VRF Gateway (Cloud Director 10.5) The Tier-0 VRF Gateway has eBGP configured and running with our core routers By default, only NAT-IPs from Tier-1 (Edges) are redistributed by that Tier-0 VRF Gateway to the Core Routers via eBGP. All the networks that we need to redistribute are correctly located in the T0 VRF routing table (that part works fine). But, if we want to advertise Connected Segments (t1c), do we need to manually modify the default BGP Distribution using the NSX-T UI or API? I can't find an option in the Cloud Director UI to do this (Cloud Director only configure the T0 with NAT redistribution).     
It is a connected subnet on the T1, so not sure why i would need static route? Design is supported for 10.4.1 from tenant side but we should be able to do the config from the NSX manager no matter t... See more...
It is a connected subnet on the T1, so not sure why i would need static route? Design is supported for 10.4.1 from tenant side but we should be able to do the config from the NSX manager no matter the VCD version?
Most likely you are missing static routes on T1. Please note that this design is supported with 10.4.1 version   
NSX-T 3.2 & VCD 10.3
Which VMware product does this relate to?
Hello, I am trying to connect a customer t1 gateway to an mpls link going to his office. To achieve this, i tried to add a service interface to the customer T1 gateway. This service interface is co... See more...
Hello, I am trying to connect a customer t1 gateway to an mpls link going to his office. To achieve this, i tried to add a service interface to the customer T1 gateway. This service interface is connected to a vlan backed segment connected to the customer office. From my org VDC, i can ping the service interface IP of the T1 gateway but I cannot go further. I cannot reach the other end (customer office). I deployed a router sitting on the vlan backed segment but this router cannot ping the T1 gateway either. It is like the service interface is not really connected to the vlan backed segment because there is no communication between the T1 gateway and the rest of the segment. Any idea?
There is nothing related to the VM name in the log. I dont think the VM name is used in these logs anyway?
Hi Matt, Can you grep the log with VM name and see the status. Below is example log snippet: 2023-08-17 09:28:54,799 | ERROR | Backend-activity-pool-87043 | CreateAutoManagedVAppActivity | [Activi... See more...
Hi Matt, Can you grep the log with VM name and see the status. Below is example log snippet: 2023-08-17 09:28:54,799 | ERROR | Backend-activity-pool-87043 | CreateAutoManagedVAppActivity | [Activity Execution] Encountered error while importing VM [vcId=fae7d8b1-a12a-4e08-b2dc-d21f33204bb3, moref=vm-15026] from VC fae7d8b1 -a12a-4e08-b2dc-d21f33204bb3 into VCD - Handle: urn:uuid:3d6c91b7-e516-4d8a-ac78-1e529829b50c, Current Phase: CreateAutoManagedVAppActivity$ImportVmFromVcPhase | activity=(com.vmware.vcloud.activities.vcresiliency.CreateAutoManagedVAp pActivity,urn:uuid:3d6c91b7-e516-4d8a-ac78-1e529829b50c) com.vmware.vcloud.api.presentation.service.BadRequestException: Cannot import auto discovered VM Linux from VC because port group [vcId=fae7d8b1-a12a-4e08-b2dc-d21f33204bb3, moref=dvportgroup-3026] is connected to VC network none, whi ch is not a valid Organization VDC network.   Cannot import auto discovered VM Linux from VC. Here Linux is VM name which I tried to import to vCD.