VMware Cloud Community
Dingo80
Enthusiast
Enthusiast

Network traffic is blocked for one or more ports - which ports are being blocked?

hi all

weve started receiving the following alert and I'm not sure why this is happening... I cant find much info about this.

 

New alert was generated at Thu Jun 02 13:46:33 BST 2016:
Info:LN1DVRES VmwareDistributedVirtualSwitch is acting abnormally since Thu Jun 02 13:46:33 BST 2016 and was last updated at Thu Jun 02 13:46:33 BST 2016

Alert Definition Name: Network traffic is blocked for one or more ports
Alert Definition Description: Network traffic is blocked for one or more ports on the vSphere Distributed Switch
Object Name : LN1DVRES
Object Type : VmwareDistributedVirtualSwitch
Alert Impact: health
Alert State : critical
Alert Type : Network
Alert Sub-Type : Performance
Object Health State: critical
Object Risk State: info
Object Efficiency State: info
Symptoms:
SYMPTOM SET - self

 

Symptom Name

Object Name

Object ID

Metric

Message Info

Network traffic is blocked for one or more ports

LN1DVRES

3b7f966d-c457-4b3b-88a4-42ada1f2308f

Summary|Number of Blocked Ports

HT above 1 > 0

 
Recommendations:
- Check the security policy on the port groups as well as any ACL rule configuration
Notification Rule Name: VROPS - Storage Availability Alert
Notification Rule Description: Storage Availability Alert
Alert ID : 5de87d21-a914-40db-906d-6af99b1e18e8
VCOps Server - hsvrops-node1.domain

when i look at the alert details it does not say which ports are affected...

ive checked the logs as well on a host and couldnt see anything in there either

im a bit stumped as to why this is happening... the security profile on the hosts has not been changed recently, its been static

has anybody seen this before?

is there a way I can see whats being blocked on the DVS ?

let me know if you need any more info...

thanks!

Reply
0 Kudos
5 Replies
mark_j
Virtuoso
Virtuoso

I've dealt with this before. You can't find the specific port in vR Ops. The summary metric is collected by vR Ops, but the instantiations are not collected. Best bet is to check the vCenter directly for blocked ports.

If you find this or any other answer useful please mark the answer as correct or helpful.
Reply
0 Kudos
Dingo80
Enthusiast
Enthusiast

ok thanks for the info... do yo know which logs I should check on vcenter ?

Reply
0 Kudos
Dingo80
Enthusiast
Enthusiast

I just found that one of our ports is showing up as blocked in vsphere... its quite possible that this is the cause of our issue

blockedport1.jpg

blockedport2.jpg

now to figure out why this is happening...

Reply
0 Kudos
hindusthan_kash
VMware Employee
VMware Employee

I could see a KB which says This can falsely trigger an alert.: VMware Knowledge Base 

Reply
0 Kudos
RickVerstegen
Expert
Expert

Check the override port policies on blocked port option.

To apply different policies for distributed ports, you configure the per-port overriding of the policies that are set at the port group level.

Edit the Blocking Policy for a Distributed Port or Uplink Port

Was I helpful? Give a kudo for appreciation!
Blog: https://rickverstegen84.wordpress.com/
Twitter: https://twitter.com/verstegenrick
Reply
0 Kudos