After a county perimeter firewall change, NSX-T Manager shows the vCenter compute manager as down and transport-node preparation stalls, while overlay VMs still enforce east-west Distributed Firewall. What should the administrator restore?
Select an answer to reveal the explanation.
Short Explanation
Think of vCenter as the phone book NSX Manager uses to talk to hosts. If a new firewall rule hangs up that management call, compute manager goes red even while already-prepared VMs keep filtering east-west. Put the Manager-to-vCenter-to-host ports back; rewriting DFW will not heal the control plane.
Full Explanation
NSX-T Manager registers vCenter as a compute manager and must reach vCenter Server plus ESXi management interfaces to inventory clusters and prepare transport nodes. A perimeter or management firewall change that blocks those paths reports the compute manager down and stalls host preparation even when the Distributed Firewall data plane on already-prepared nodes continues to enforce east-west policy. Recreating DFW sections, swapping identity sources, or installing a Carbon Black sensor on Manager does not restore that control-plane connectivity. Open the documented management ports and verify Manager, vCenter, and host reachability before changing security policy.