VMware vDefend

  • 1.  Security Service Platform Fail to deploy

    Posted Jul 04, 2025 03:24 PM

    Hello,

    I'm trying to deploy the SSP 5.0 instances in order to finally test this additional set of tools on a lab test environment, and if it works fine do it also in production.

    The current issue that I've is after the pre-check, so during the installation of the actual vms where the solution is running.
    The step is the workload cluster:

    Running 9/17 tasks: [Create workload cluster] Nodes status: 0/3 running [nsx-dev-ssp-km7q4 Provisioned, nsx-dev-ssp-md-0-n8c6r-lh729 Pending, nsx-dev-ssp-md-0-n8c6r-xb2gj Pending, ]

    it stays like this for a lot, after reaching a timeout issue:



    the current network topology is:
    ssp installer running on the same network of vcenter and nsx
    ssp running in nsx overlay segment that doesn't have any block in the firewall in between vcenter/nsx network to ssp network.

    Failed 9/17 tasks: [Create workload cluster] Timed out while waiting for all Kubernetes nodes to reach the 'Ready' state. Ensure the nodes are correctly configured, and there are no underlying issues. Check the logs for more details. Nodes status: 0/3 running [nsx-dev-ssp-km7q4 Provisioned, nsx-dev-ssp-md-0-n8c6r-lh729 Pending, nsx-dev-ssp-md-0-n8c6r-xb2gj Pending, ]





  • 2.  RE: Security Service Platform Fail to deploy

    Broadcom Employee
    Posted Jul 08, 2025 07:47 PM

    Hello Giovanni, would it be possible to send us the SSPI support bundle please. If attaching it on this forum is not possible, please do open a support ticket and attach the bundle.




  • 3.  RE: Security Service Platform Fail to deploy

    Posted Jul 09, 2025 02:49 PM

    seems the main issue was the missing port opened on the firewall between the installer and the ssp node networks.
    Port 6443 for sure from node to installer and also 9092 from nsx, hosts and so on... So I went through by checking the drops with a firewall colleagues.




  • 4.  RE: Security Service Platform Fail to deploy

    Posted Jul 09, 2025 02:49 PM

    Hello. Curios if you had this resolved. I am running into the same issue.. However mine shows that the controller VM is running and the worker nodes have failed..  I noticed your image still has the status in progress, wait for it to time out and see if the Controller node is running.




  • 5.  RE: Security Service Platform Fail to deploy

    Posted 7 hours ago

    Hello, 

    yep is has been resolved by goind to the documentation and open the missing firewall ports needed for the communication from the worker network to the esxi and nsx manager.

    https://ports.broadcom.com/home/VMware-vDefend

    -------------------------------------------