Parks Endpoint Protection via Guest Introspection shows partner service VMs unhealthy. Transport nodes are prepared and Distributed Firewall Application policy is unchanged, but the service insertion network cannot ping the partner SVM. What should the administrator fix first?
Select an answer to reveal the explanation.
Short Explanation
Guest Introspection is a sidecar van on its own service road. If that road cannot reach the partner SVM, endpoint protection looks sick even while DFW Application rules are still fine. Fix the service-insertion network first.
Full Explanation
NSX-T Guest Introspection and partner Endpoint Protection depend on the service insertion network to reach the partner service VM. When that network is down, GI agents report unhealthy and partner EPP fails even if transport nodes remain prepared and Distributed Firewall Application policy is unchanged. Broadening DFW, substituting Carbon Black Cloud, or using Workspace ONE Access network ranges does not restore SVM connectivity. Repair addressing, routing, and firewall allows on the service insertion network, then recheck partner health.