Views:

You may encounter the following symptoms when deploying Deep Security Virtual Appliance:

 

1) Successfully deployed the DSVA but activation is failing

image.png

 

2) The DSVA from vCenter view shows only 3 IP address instead of the expected 5 IP address

image.png

 

3) From NSX-T console, the Criteria Alarms shows Partner Channel Down for Endpoint Protection

image.png



Troubleshooting

 

  1. Login to the DSVA and switch to its terminal console.
  2. Go to /var/opt/ds_agent/slowpath/ and inspect the configuration files dsva-ovf.env and dsva-ovf.xml 
  3. Verify the IP address assigned and network configuration if same as NSX-T Static IP pool
    image.png
    image.png
  4. Check the /var/opt/messages log and search the IP address that assigned to DSVA and show the IP already used by other.
    image.png
  5. From NSX-T manager console, confirm the IP already in use by ESX host for TEP IP addresses.
    image.png

Workaround

1) Delete the current deployment plan and re-deploy DSVA . Change the NIC0 to use DHCP instead of Static IP Pool

Here is an article from VMware that addresses the same issue: Service Status Unknown or Endpoint Protection fails to get IP Address (vmware.com)