VMware NSX

  • 1.  NSX Application Platform Automation - Failure Deploying TKGs

    Posted Apr 27, 2025 04:54 AM

    Hi Everyone..

    I have a lab environment that is Nested and using self signed Certs.

    Running NSX 4.2.1.3, vSphere 8U2.  Using the NAPP Automation appliance 4.2.0.24095980 

    When I use the NAPP Automation appliance to deploy NAPP, All checks look good and pass.  During the deployment when it hits the "Login to Supervisor Cluster" stage I receive the following error.

    "function":"LoginToWCPCluster","level":"debug","msg":"[TRY 9/10]: time=\"2025-04-26T13:31:56Z\" level=error msg=\"Error occurred during HTTP request: Get \\\"https://172.20.12.33/wcp/loginbanner\\\": x509: certificate has expired or is not yet valid: current time 2025-04-26T13:31:56Z is before 2025-04-26T21:35:03Z\"\ntime=\"2025-04-26T13:31:56Z\"

    Thoughts? Hints?  Thanks..



  • 2.  RE: NSX Application Platform Automation - Failure Deploying TKGs

    Posted Apr 28, 2025 03:05 PM

    Hello 

    It is documented.

    Supervisor Cluster Certification Error

    Broadcom remove preview
    Supervisor Cluster Certification Error
    Logging in to the Supervisor cluster fails because of a Certificate error.
    View this on Broadcom >

    Regards




  • 3.  RE: NSX Application Platform Automation - Failure Deploying TKGs

    Posted Apr 29, 2025 05:11 PM

    Thanks very much for the info.

    Funny thing is I seen this document when I was searching for the issue and the problem is listed differently I a never changed my IP address of the vCenter server.  None the less it worked..

    Lets see how far I can get with the deployment now.

    Have a good one.




  • 4.  RE: NSX Application Platform Automation - Failure Deploying TKGs

    Posted Apr 30, 2025 09:35 AM

    If you're doing a new deployment (and you're on a recent-ish version of NSX) you probably want to be using the Security Services Platform instead of NAPP. You can see more about SSP at VMware vDefend: Accelerate Enterprise's Zero Trust Private Cloud Journey with Micro-segmentation and NDR Innovations and Security Services Platform

    As best I can tell SSP is the same code base as NAPP (presumably with some minor updates and such), but it handles K8s rather than considering that an external component. (I know the NAPP Automation Applicance can handle deployment of K8s, but once it's deployed K8s isn't further managed/lifecycled/etc.)




  • 5.  RE: NSX Application Platform Automation - Failure Deploying TKGs

    Posted Apr 30, 2025 12:40 PM

    Thanks for the info.  I am setting up my lab environment and looking at doing Youtube Videos on it for my Channel.  So from what I can see looks like the NAPP automation appliance is pretty much dead now.. Is the SSP GA'd?  Where do I download the SSP Appliance?  I do not see it in the NSX download section only the NAPP and NAPP Automation appliances.

    BTW I am a VMUG Advantage member so this is how I get my downloads..

    Thanks again




  • 6.  RE: NSX Application Platform Automation - Failure Deploying TKGs

    Posted Apr 30, 2025 05:46 PM

    SSP is GA as of mid March. I don't know where/if it's available under VMUG, but on the main Broadcom support portal, it's available under the "VMware Firewall" product.