0% found this document useful (0 votes)
64 views37 pages

VMware NSX 4.0.0.1 Release Notes

The VMware NSX 4.0.0.1 Release Notes detail the new features and enhancements in the NSX 4.0 release, including IPv6 support, the ability to block malicious IPs, and improvements to DHCP configuration. The document also outlines feature deprecations, API changes, and system requirements for upgrading to this version. Additionally, it highlights compatibility with the NSX Application Platform and provides guidance on installation and upgrade processes.

Uploaded by

mipij31459
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
64 views37 pages

VMware NSX 4.0.0.1 Release Notes

The VMware NSX 4.0.0.1 Release Notes detail the new features and enhancements in the NSX 4.0 release, including IPv6 support, the ability to block malicious IPs, and improvements to DHCP configuration. The document also outlines feature deprecations, API changes, and system requirements for upgrading to this version. Additionally, it highlights compatibility with the NSX Application Platform and provides guidance on installation and upgrade processes.

Uploaded by

mipij31459
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 37

6/1/25, 3:37 PM VMware NSX 4.0.0.

1 Release Notes

/ VMware® Cloud Infrastructure Software / VMware NSX / VMware NSX 4.0 / Release Notes / VMware NSX 4.0.0.1 Release Notes

VMware NSX 4.0

Version 4.0 English

Search this product 

VMware NSX 4.0.0.1 Release Notes


Last Updated January 17, 2025
Product Menu 

This document contains the following sections


Introduction
What's New
Feature Deprecation
API Deprecation and Behavior Changes
Compatibility and System Requirements
Upgrade Notes for This Release
API and CLI Resources
Available Languages
Document Revision History
Resolved Issues
Known Issues

Introduction

VMware NSX 4.0 | 02 AUG 2022 | Build 20159689


Check for additions and updates to these release notes.

What's New
NSX 4.0.0.1 is a major release offering new features in all the verticals of NSX: networking, security and services. Some of the major
enhancements are the following:
IPv6 external-facing Management Plane introduces support for IPv6 communication from external systems with the NSX
management cluster (Local Manager only).
Block Malicious IPs in Distributed Firewall is a new capability that allows the ability to block traffic to and from Malicious IPs.
In addition to the features, many other capabilities are added in every area on the product. More details are available below in the
detailed description of added features.
Product Name Change: With the release of 4.0.0.1 the product name changes from "VMware NSX-T Data Center" to "VMware NSX."
This new name better reflects the multi-faceted value that NSX brings to customers. This update is apparent in the product graphical
user interface as well as documentation. This change has no impact to the functionality of the product or changes to the API that
impacts compatibility with previous releases.
Layer 3 Networking

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 1/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

IPv6 external-facing Management Plane introduces support for IPv6 communication from external systems with the NSX
management cluster (Local Manager only). The NSX Manager now supports dual-stack (IPv4 and IPv6) in the external management
interface. IPV6-only deployments are not supported in this release.
The following external communication and systems are supported:
Access to NSX User Interface (UI) through IPv6
Access to NSX API through IPv6
IPv6 communication with vCenter
– In this release vCenter services and clients using vCenter Extension Manager to communicate with NSX Manager, such as
vLCM, WCP and Supervisor Cluster, will be using IPv4 to connect to NSX Manager.
IPv6 syslog
IPv6 SNMP
IPv6 SSH
IPv6 SFTP (Backup & Restore)
IPv6 communication with DNS server (name resolution)
IPv6 communication with NTP server
IPv6 Cluster VIP
IPv6 communication with LDAP/AD servers, for user authentication and IDFW
IPv6 interaction with Operations tools: vRNI, vRLI & vROPs
IPv6 support for telemetry/VAC
Internal T0-T1 transit subnet prefix change after Tier0 creation allows users to change the prefix used for the T0-T1 transit
subnet after the Tier-0 creation. Before this feature the user was allowed to change the default value (100.64.0.0/16) only at the Tier-
0 creation time.
Networking Services (NAT, DHCP, DNS)
NAT support for Policy-based VPN on T0/T1 Gateway allows the configuration of DNAT/NO-DNAT rule that matches traffic
decapsulated from the Policy-based VPN. At the time we want to translate the Destination IP for the traffic decapsulated from the
VPN we can configure DNAT/NO-DNAT and select "match" for the policy based VPN. The default behavior will be kept to bypass
which means it does not match traffic decapsulated from policy-based VPN.
DHCP UI configuration workflow improvement offers in a simpler and easier configuration of Local DHCP server; Gateway DHCP
server or DHCP Relay . It also offers better visibility and monitoring options.
DHCP Standby relocation improves the availability for the DHCP server, allowing the configuration of standby relocation where, in
case of failure, the new standby Edge will be elected.
Edge platform
Edge relocate API gives the option when an Edge VM enters maintenance mode, to gracefully relocate all T1 auto allocated SRs to
other Edge VMs.
Maintain Edge Node parameters during upgrade - post-upgrade all user-edited settings of Edge Node will be preserved and not
reset to default.
Distributed Firewall
Block Malicious IPs in Distributed Firewall is a new capability that allows the ability to block traffic to and from Malicious IPs. This
is achieved by ingesting a feed of Malicious IPs provided by Vmware Contexa. This feed is automatically updated multiple times a
day so that the environment is protected with the latest malicious IPs. For existing environments the feature will need to be turned
on explicitly. For new environments, the feature will be default enabled.
NSX Distributed Firewall has now added support for these following versions for physical servers: RHEL 8.2, 8.4, Ubuntu 20.04,
CentOS 8.2, 8.4.
Federation
Physical servers are now supported are on Local Managers that are part of a Federation. Physical servers can now be part of
groups defined on Global Manager, those groups can then be used in firewall rules (DFW or Gateway Firewall).
Service insertion
Service Insertion has now added additional alarms to monitor the health and liveness of the Service Insertion components.
NSX Application Platform and Associated Services
NSX 4.0.0.1 is compatible with NSX Application Platform 3.2.1 version, along with the related NSX features (NSX Intelligence, NSX
Network Detection and Response, NSX Malware Prevention, and NSX Metrics).
If you are running NSX Application Platform 3.2.0, you must upgrade to NSX Application Platform 3.2.1 (or any subsequent
maintenance release) before you can upgrade to NSX 4.0.0.1.
Installation and upgrade
Faster Upgrades - benefit from up to a 10% reduction in NSX upgrade time overall to use the maintenance windows more
effectively.
Monitoring - New alarms for lifecycle status of physical servers (install, uninstall, upgrade).
https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 2/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Usability Enhancements:
Generate system notifications when newer NSX versions become available.
Operations and Monitoring
Live Traffic Analysis & Traceflow support for VPN - get an end-to-end view of live packets in a VPN tunnel using Traceflow or the
Live Traffic Analysis Tool
Edge Support for Live Traffic Analysis - use the Live Traffic Analysis tool to perform packet capture on NSX Edge interfaces
Enhancements to events, alarms & operations - several known issues with the Live Traffic Analysis tool and Traceflow have been
addressed in this release. Also, high latency alerts have been added in the the management and network infrastructure.
AAA and Platform Security
Improved Local User Password Configuration - NSX supports additional complexity requirements to align with newer industry
regulations
API
Logging of Deprecated APIs: The system will flag in the logs when an API involved is deprecated in order to simplify the transition
from deprecated APIs to their replacement.
Licensing
License Enforcement - Enhanced feature-level enforcement on NSX Firewall license editions, restricting access to features based
on license edition. New users are able to access only those features that are available in the edition that they have purchased.
Existing users who have used features that are not in their license edition are restricted to only viewing the objects; create and edit
will be disallowed.

Feature Deprecation
Support of Non-VIO OpenStack and KVM: NSX will no longer support either KVM based hypervisors or OpenStack distributions
from third-party vendors. Support for VMware Integration OpenStack (VIO) remains. Please see the VMware Product Interoperability
Matrix for details on which versions of NSX and VIO are compatible.
NSX N-VDS Host Switch support: NSX 3.0.0 and later has the capability to run on the vSphere VDS switch version 7.0 and later.
This provides a tighter integration with vSphere and easier NSX adoption for customers adding NSX to their vSphere environment.
Please be aware that VMware has removed support of the NSX N-VDS virtual switch on ESXi hosts starting this release, NSX
4.0.0.1. N-VDS will remain the supported virtual switch on NSX Edge nodes, native public cloud NSX agents, and bare metal
workloads.
New deployments of NSX and vSphere must take advantage of this close integration and deploy using VDS switch version 7.0 and
later. In addition, for existing deployments of NSX that use the N-VDS on ESXi hosts, VMware recommends you move toward the use
of NSX on VDS before upgrading to this release. To make this process easy, VMware has provided both a CLI based switch migration
tool, which was first made available in NSX-T 3.0.2 (see VMware knowledge base article 87379) and a GUI based Upgrade Readiness
Tool, which was first made available in the NSX-T 3.1.1 getting started wizard (see VMware NSX-T Data Center 3.1.1 Release Notes for
more details on this tool). In NSX-T 3.2.2, the Upgrade Evaluation tool was integrated as part of the NSX upgrade bundle (see VMware
NSX-T Data Center 3.2.2 Release Notes). Use the appropriate tool for your release upgrade.
The following deployment considerations are recommended when moving from N-VDS to VDS before upgrading to this release:
The N-VDS and VDS APIs are different, and the backing type for VM and vmKernel interface APIs for the N-VDS and VDS switches
are also different. As you move to use VDS in your environment, you will have to invoke the VDS APIs instead of N-VDS APIs. This
ecosystem change will have to be made before converting the N-VDS to VDS. Refer to KB https://kb.vmware.com/s/article/79872 for
more details.
Note: There are no changes to N-VDS or VDS APIs.
VDS is configured through vCenter, while N-VDS was vCenter independent. With the deprecation of N-VDS, NSX will be closely tied
to vCenter and vCenter will be required to enable NSX in vSphere environments.
NSX Distributed Firewall has now deprecated support for these following versions of physical servers: RHEL 7.8, 8.0, and 8.3,
CentOS 7.8, 8.0, and 8.3
NSX Advanced Load Balancing Policy API and UI deprecation
Configuration of NSX Advanced Load Balancer(Avi), using NSX Advanced Load Balance Policy API and UI, is deprecated starting
NSX 4.0.0.1 and will be removed completely in future releases. We recommend you use NSX Advanced Load Balancer (Avi) UI and
API directly for the configuration of Load Balancers in NSX-T integration across all deployment models.
Installation of NSX Advanced Load Balancer appliance cluster and cross-launch of NSX Advanced Load Balancer UI from the NSX-
T manager will continue to be supported.
The users consuming NSX Advanced Load Balance Policy API and UI in the earlier releases of NSX-T 3.1.x, NSX-T 3.2.0, and NSX-
T 3.2.1 upgrading to NSX 4.0.0.1 will need to clean the NSX Advanced Load Balance Policy configuration in the NSX
manager(using Deactive workflow) and will retain the configuration in VMware NSX Advanced Load balancer (Avi). From there on,
users can consume Load balancing functionality directly from VMware NSX Advanced Load balancer (Avi).
Migration of NSX-V Load Balancer for User-Defined Topology Lift-and-Shift Migration is not be supported in NSX 4.0.0.1.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 3/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

API Deprecation and Behavior Changes


New pages on API deprecation of removal have been added to the NSX API Guide to simplify API consumption. Those will list the
deprecated APIs and Types, and the removed APIs and Types.
The following MP APIs for service insertion have been removed. Their corresponding UI have also been removed.

Removed API Replacement

GET /api/v1/serviceinsertion/excludelist GET /policy/api/v1/infra/settings/service-


insertion/security/exclude-list

PUT /api/v1/serviceinsertion/excludelist PUT /policy/api/v1/infra/settings/service-


insertion/security/exclude-list

POST /api/v1/serviceinsertion/excludelist?action=add_member PATCH /policy/api/v1/infra/settings/service-


insertion/security/exclude-list

POST /api/v1/serviceinsertion/excludelist? PATCH /policy/api/v1/infra/settings/service-


action=remove_member insertion/security/exclude-list

GET /api/v1/serviceinsertion/status GET /policy/api/v1/infra/settings/service-insertion/security/status

GET /api/v1/serviceinsertion/status/<context-type> GET /policy/api/v1/infra/settings/service-insertion/security/status

PUT /api/v1/serviceinsertion/status/<context-type> PATCH /policy/api/v1/infra/settings/service-


insertion/security/status

GET /api/v1/serviceinsertion/sections GET /policy/api/v1/infra/domains/<domain-id>/redirection-policies

POST /api/v1/serviceinsertion/sections PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>

POST /api/v1/serviceinsertion/sections?action=create_with_rules PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>

GET /api/v1/serviceinsertion/sections/<section-id> GET /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>

POST /api/v1/serviceinsertion/sections/<section-id>? GET /policy/api/v1/infra/domains/<domain-id>/redirection-


action=list_with_rules policies/<redirection-policy-id>/rules

DELETE /api/v1/serviceinsertion/sections/<section-id> DELETE /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>

PUT /api/v1/serviceinsertion/sections/<section-id> PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>

POST /api/v1/serviceinsertion/sections/<section-id>? PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


action=update_with_rules policies/<redirection-policy-id>

POST /api/v1/serviceinsertion/sections/<section-id>? PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


action=revise policies/<redirection-policy-id>

POST /api/v1/serviceinsertion/sections/<section-id>? PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


action=revise_with_rules policies/<redirection-policy-id>

GET /api/v1/serviceinsertion/sections/<section-id>/rules/<rule-id> GET /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>/rules/<rule-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 4/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Removed API Replacement

GET /serviceinsertion/sections/<section-id>/rules GET /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>/rules

POST /serviceinsertion/sections/<section-id>/rules PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>/rules/<rule-id>

PUT /api/v1/serviceinsertion/sections/<section-id>/rules/<rule-id> PUT /policy/api/v1/infra/domains/<domain-id>/redirection-


policies/<redirection-policy-id>/rules/<rule-id>

POST /api/v1/serviceinsertion/sections/<section-id>/rules? PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


action=create_multiple policies/<redirection-policy-id>

POST /api/v1/serviceinsertion/sections/<section-id>/rules/<rule- PATCH /policy/api/v1/infra/domains/<domain-id>/redirection-


id>?action=revise policies/<redirection-policy-id>

DELETE /api/v1/serviceinsertion/sections/<section- DELETE /policy/api/v1/infra/domains/<domain-id>/redirection-


id>/rules/<rule-id> policies/<redirection-policy-id>/rules/<rule-id>

GET /api/v1/fabric/nodes/<node-id>/network/interfaces GET /transport-nodes/<transport-node-id>/network/interface

NSX Advanced Load Balancing API Deprecation:

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Auth Token PUT /policy/api/v1/infra/alb-auth-token Not Applicable

ALB Controller Version GET /policy/api/v1/infra/alb-controller- GET /api/initial-data


version

ALB Analytics Profile


GET /policy/api/v1/infra/alb-analytics- GET /api/analyticsprofile
profiles

DELETE /policy/api/v1/infra/alb-analytics- GET /api/analyticsprofile


profiles/<alb-analyticsprofile-id>

GET /policy/api/v1/infra/alb-analytics- DELETE


profiles/<alb-analyticsprofile-id> /api/analyticsprofile/{uuid}GET /api/analytic
sprofile/{uuid}

PATCH /policy/api/v1/infra/alb-analytics- PATCH /api/analyticsprofile/{uuid}


profiles/<alb-analyticsprofile-id>

PUT /policy/api/v1/infra/alb-analytics- PUT /api/analyticsprofile/{uuid}


profiles/<alb-analyticsprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 5/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Application Persistence Profiles


GET /policy/api/v1/infra/alb-application- GET /api/applicationpersistenceprofile
persistence-profiles

DELETE /policy/api/v1/infra/alb- DELETE


application-persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

GET /policy/api/v1/infra/alb-application- GET


persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

PATCH /policy/api/v1/infra/alb-application- PATCH


persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

PUT /policy/api/v1/infra/alb-application- PUT


persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

ALB Application Profiles


GET /policy/api/v1/infra/alb-application- GET /api/applicationprofile
profiles

DELETE /policy/api/v1/infra/alb- DELETE /api/applicationprofile/{uuid}


application-profiles/<alb-applicationprofile-
id>

GET /policy/api/v1/infra/alb-application- GET /api/applicationprofile/{uuid}


profiles/<alb-applicationprofile-id>

PATCH /policy/api/v1/infra/alb-application- PATCH /api/applicationprofile/{uuid}


profiles/<alb-applicationprofile-id>

PUT /policy/api/v1/infra/alb-application- PUT /api/applicationprofile/{uuid}


profiles/<alb-applicationprofile-id>

ALB Auth Profiles


GET /policy/api/v1/infra/alb-auth-profiles GET /api/authprofile

DELETE /policy/api/v1/infra/alb-auth- DELETE /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

GET /policy/api/v1/infra/alb-auth- GET /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

PATCH /policy/api/v1/infra/alb-auth- PATCH /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

PUT /policy/api/v1/infra/alb-auth- PUT /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 6/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Auto Scale Launch Configs


GET /policy/api/v1/infra/alb-auto-scale- GET /api/autoscalelaunchconfig
launch-configs

DELETE /policy/api/v1/infra/alb-auto-scale- DELETE /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

GET /policy/api/v1/infra/alb-auto-scale- GET /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

PATCH /policy/api/v1/infra/alb-auto-scale- PATCH /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

PUT /policy/api/v1/infra/alb-auto-scale- PUT /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

ALB DNS Policies


GET /policy/api/v1/infra/alb-dns-policies GET /api/dnspolicy

DELETE /policy/api/v1/infra/alb-dns- DELETE /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

GET /policy/api/v1/infra/alb-dns- GET /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

PATCH /policy/api/v1/infra/alb-dns- PATCH /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

PUT /policy/api/v1/infra/alb-dns- PUT /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

ALB Error Page Bodies


GET /policy/api/v1/infra/alb-error-page- GET /api/errorpagebody
bodies

DELETE /policy/api/v1/infra/alb-error- DELETE /api/errorpagebody/{uuid}


page-bodies/<alb-errorpagebody-id>

GET /policy/api/v1/infra/alb-error-page- GET /api/errorpagebody/{uuid}


bodies/<alb-errorpagebody-id>

PATCH /policy/api/v1/infra/alb-error-page- PATCH /api/errorpagebody/{uuid}


bodies/<alb-errorpagebody-id>

PUT /policy/api/v1/infra/alb-error-page- PUT /api/errorpagebody/{uuid}


bodies/<alb-errorpagebody-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 7/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Error Page Profiles


GET /policy/api/v1/infra/alb-error-page- GET /api/errorpageprofile
profiles

DELETE /policy/api/v1/infra/alb-error- DELETE /api/errorpageprofile/{uuid}


page-profiles/<alb-errorpageprofile-id>

GET /policy/api/v1/infra/alb-error-page- GET /api/errorpageprofile/{uuid}


profiles/<alb-errorpageprofile-id>

PATCH /policy/api/v1/infra/alb-error-page- PATCH /api/errorpageprofile/{uuid}


profiles/<alb-errorpageprofile-id>

PUT /policy/api/v1/infra/alb-error-page- PUT /api/errorpageprofile/{uuid}


profiles/<alb-errorpageprofile-id>

ALB HTTP Policy Sets


GET /policy/api/v1/infra/alb-http-policy-sets GET /api/httppolicyset

DELETE /policy/api/v1/infra/alb-http-policy- DELETE /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

GET /policy/api/v1/infra/alb-http-policy- GET /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

PATCH /policy/api/v1/infra/alb-http-policy- PATCH /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

PUT /policy/api/v1/infra/alb-http-policy- PUT /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

ALB Hardware Security Module Groups


GET /policy/api/v1/infra/alb-hardware- GET /api/hardwaresecuritymodulegroup
security-module-group

DELETE /policy/api/v1/infra/alb-hardware- DELETE


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

GET /policy/api/v1/infra/alb-hardware- GET


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

PATCH /policy/api/v1/infra/alb-hardware- PATCH


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

PUT /policy/api/v1/infra/alb-hardware- PUT


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 8/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Health Monitors


GET /policy/api/v1/infra/alb-health- GET /api/healthmonitor
monitors

DELETE /policy/api/v1/infra/alb-health- DELETE /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

GET /policy/api/v1/infra/alb-health- GET /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

PATCH /policy/api/v1/infra/alb-health- PATCH /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

PUT /policy/api/v1/infra/alb-health- PUT /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

ALB IP Addr Groups


GET /policy/api/v1/infra/alb-ip-addr-groups GET /api/ipaddrgroup

DELETE /policy/api/v1/infra/alb-ip-addr- DELETE /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

GET /policy/api/v1/infra/alb-ip-addr- GET /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

PATCH /policy/api/v1/infra/alb-ip-addr- PATCH /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

PUT /policy/api/v1/infra/alb-ip-addr- PUT /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

ALB L4 Policy Sets


GET /policy/api/v1/infra/alb-l4-policy-sets GET /api/l4policyset

DELETE /policy/api/v1/infra/alb-l4-policy- DELETE /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

GET /policy/api/v1/infra/alb-l4-policy- GET /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

PATCH /policy/api/v1/infra/alb-l4-policy- PATCH /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

PUT /policy/api/v1/infra/alb-l4-policy- PUT /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 9/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Network Profiles


GET /policy/api/v1/infra/alb-network- GET /api/networkprofile
profiles

DELETE /policy/api/v1/infra/alb-network- DELETE /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

GET /policy/api/v1/infra/alb-network- GET /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

PATCH /policy/api/v1/infra/alb-network- PATCH /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

PUT /policy/api/v1/infra/alb-network- PUT /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

ALB Network Security Policies


GET /policy/api/v1/infra/alb-network- GET /api/networksecuritypolicy
security-policies

DELETE /policy/api/v1/infra/alb-network- DELETE /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

GET /policy/api/v1/infra/alb-network- GET /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

PATCH /policy/api/v1/infra/alb-network- PATCH /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

PUT /policy/api/v1/infra/alb-network- PUT /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

ALB Onboarding Workflow PUT /policy/api/v1/infra/alb-onboarding- Not Applicable.


workflowDELETE /policy/api/v1/infra/alb-
onboarding-workflow/<managed-by>

ALB PKI Profiles


GET /policy/api/v1/infra/alb-pki-profiles GET /api/pkiprofile

DELETE /policy/api/v1/infra/alb-pki- DELETE /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

GET /policy/api/v1/infra/alb-pki- GET /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

PATCH /policy/api/v1/infra/alb-pki- PATCH /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

PUT /policy/api/v1/infra/alb-pki- PUT /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 10/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Pool Group Deployment Policies


GET /policy/api/v1/infra/alb-pool-group- GET /api/poolgroupdeploymentpolicy
deployment-policies

DELETE /policy/api/v1/infra/alb-pool- DELETE


group-deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

GET /policy/api/v1/infra/alb-pool-group- GET


deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

PATCH /policy/api/v1/infra/alb-pool-group- PATCH


deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

PUT /policy/api/v1/infra/alb-pool-group- PUT


deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

ALB Pool Groups


GET /policy/api/v1/infra/alb-pool-groups GET /api/poolgroup

DELETE /policy/api/v1/infra/alb-pool- DELETE /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

GET /policy/api/v1/infra/alb-pool- GET /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

PATCH /policy/api/v1/infra/alb-pool- PATCH /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

PUT /policy/api/v1/infra/alb-pool- PUT /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

ALB Pools
GET /policy/api/v1/infra/alb-pools GET /api/pool

DELETE /policy/api/v1/infra/alb-pools/<alb- DELETE /api/pool/{uuid}


pool-id>

GET /policy/api/v1/infra/alb-pools/<alb- GET /api/pool/{uuid}


pool-id>

PATCH /policy/api/v1/infra/alb-pools/<alb- PATCH /api/pool/{uuid}


pool-id>

PUT /policy/api/v1/infra/alb-pools/<alb- /PUT /api/pool/{uuid}


pool-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 11/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Priority Labels


GET /policy/api/v1/infra/alb-priority-labels GET /api/prioritylabels

DELETE /policy/api/v1/infra/alb-priority- DELETE /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

GET /policy/api/v1/infra/alb-priority- GET /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

PATCH /policy/api/v1/infra/alb-priority- PATCH /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

PUT /policy/api/v1/infra/alb-priority- PUT /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

ALB Protocol Parsers


GET /policy/api/v1/infra/alb-protocol- GET /api/protocolparser
parsers

DELETE /policy/api/v1/infra/alb-protocol- DELETE /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

GET /policy/api/v1/infra/alb-protocol- GET /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

PATCH /policy/api/v1/infra/alb-protocol- PATCH /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

PUT /policy/api/v1/infra/alb-protocol- PUT /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

ALB Security Policies


GET /policy/api/v1/infra/alb-security- GET /api/securitypolicy
policies

DELETE /policy/api/v1/infra/alb-security- DELETE /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

GET /policy/api/v1/infra/alb-security- GET /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

PATCH /policy/api/v1/infra/alb-security- PATCH /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

PUT /policy/api/v1/infra/alb-security- PUT /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 12/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Server Auto Scale Policies


GET /policy/api/v1/infra/alb-server-auto- GET /api/serverautoscalepolicy
scale-policies

DELETE /policy/api/v1/infra/alb-server- DELETE /api/serverautoscalepolicy/{uuid}


auto-scale-policies/<alb-
serverautoscalepolicy-id>

GET /policy/api/v1/infra/alb-server-auto- GET /api/serverautoscalepolicy/{uuid}


scale-policies/<alb-serverautoscalepolicy-
id>

PATCH /policy/api/v1/infra/alb-server-auto- PATCH /api/serverautoscalepolicy/{uuid}


scale-policies/<alb-serverautoscalepolicy-
id>

PUT /policy/api/v1/infra/alb-server-auto- PUT /api/serverautoscalepolicy/{uuid}


scale-policies/<alb-serverautoscalepolicy-
id>+

ALB SSL Key And Certificates


GET /policy/api/v1/infra/alb-ssl-key-and- GET /api/sslkeyandcertificate
certificates

DELETE /policy/api/v1/infra/alb-ssl-key- DELETE /api/sslkeyandcertificate/{uuid}


and-certificates/<alb-sslkeyandcertificate-
id>

GET /policy/api/v1/infra/alb-ssl-key-and- GET /api/sslkeyandcertificate/{uuid}


certificates/<alb-sslkeyandcertificate-id>

PATCH /policy/api/v1/infra/alb-ssl-key-and- PATCH /api/sslkeyandcertificate/{uuid}


certificates/<alb-sslkeyandcertificate-id>

PUT /policy/api/v1/infra/alb-ssl-key-and- PUT /api/sslkeyandcertificate/{uuid}


certificates/<alb-sslkeyandcertificate-id>

ALB SSL Profiles


GET /policy/api/v1/infra/alb-ssl- GET /api/sslprofile
profilesDELETE /policy/api/v1/infra/alb-ssl-
profiles/<alb-sslprofile-id>

DELETE /policy/api/v1/infra/alb-ssl- DELETE /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

GET /policy/api/v1/infra/alb-ssl- GET /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

PATCH /policy/api/v1/infra/alb-ssl- PATCH /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

PUT /policy/api/v1/infra/alb-ssl- PUT /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 13/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB SSO Policies


GET /policy/api/v1/infra/alb-sso-policies GET /api/ssopolicy

DELETE /policy/api/v1/infra/alb-sso- DELETE /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

GET /policy/api/v1/infra/alb-sso- GET /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

PATCH /policy/api/v1/infra/alb-sso- PATCH /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

PUT /policy/api/v1/infra/alb-sso- PUT /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

ALB String Groups


GET /policy/api/v1/infra/alb-string-groups GET /api/stringgroup

DELETE /policy/api/v1/infra/alb-string- DELETE /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

GET /policy/api/v1/infra/alb-string- GET /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

PATCH /policy/api/v1/infra/alb-string- PATCH /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

PUT /policy/api/v1/infra/alb-string- PUT /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

ALB Traffic Clone Profiles


GET /policy/api/v1/infra/alb-traffic-clone- GET /api/trafficcloneprofile
profiles

DELETE /policy/api/v1/infra/alb-traffic- DELETE /api/trafficcloneprofile/{uuid}


clone-profiles/<alb-trafficcloneprofile-id>

GET /policy/api/v1/infra/alb-traffic-clone- GET /api/trafficcloneprofile/{uuid}


profiles/<alb-trafficcloneprofile-id>

PATCH /policy/api/v1/infra/alb-traffic-clone- PATCH /api/trafficcloneprofile/{uuid}


profiles/<alb-trafficcloneprofile-id>

PUT /policy/api/v1/infra/alb-traffic-clone- PUT /api/trafficcloneprofile/{uuid}


profiles/<alb-trafficcloneprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 14/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Virtual Services


GET /policy/api/v1/infra/alb-virtual-services GET /api/virtualservice

DELETE /policy/api/v1/infra/alb-virtual- DELETE /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

GET /policy/api/v1/infra/alb-virtual- GET /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

PATCH /policy/api/v1/infra/alb-virtual- PATCH /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

PUT /policy/api/v1/infra/alb-virtual- PUT /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

ALB VS Data Script Sets


GET /policy/api/v1/infra/alb-vs-data-script- GET /api/vsdatascriptset
sets

DELETE /policy/api/v1/infra/alb-vs-data- DELETE /api/vsdatascriptset/{uuid}


script-sets/<alb-vsdatascriptset-id>

GET /policy/api/v1/infra/alb-vs-data-script- GET /api/vsdatascriptset/{uuid}


sets/<alb-vsdatascriptset-id>

PATCH /policy/api/v1/infra/alb-vs-data- PATCH /api/vsdatascriptset/{uuid}


script-sets/<alb-vsdatascriptset-id>

PUT /policy/api/v1/infra/alb-vs-data-script- PUT /api/vsdatascriptset/{uuid}


sets/<alb-vsdatascriptset-id>

ALB VS Vips
GET /policy/api/v1/infra/alb-vs-vips GET /api/vsvip

DELETE /policy/api/v1/infra/alb-vs- DELETE /api/vsvip/{uuid}


vips/<alb-vsvip-id>

GET /policy/api/v1/infra/alb-vs-vips/<alb- GET /api/vsvip/{uuid}


vsvip-id>

PATCH /policy/api/v1/infra/alb-vs- PATCH /api/vsvip/{uuid}


vips/<alb-vsvip-id>

PUT /policy/api/v1/infra/alb-vs-vips/<alb- PUT /api/vsvip/{uuid}


vsvip-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 15/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB WAF CRS


GET /policy/api/v1/infra/alb-waf-crs GET /api/wafcrs

DELETE /policy/api/v1/infra/alb-waf- DELETE /api/wafcrs/{uuid}


crs/<alb-wafcrs-id>

GET /policy/api/v1/infra/alb-waf-crs/<alb- GET /api/wafcrs/{uuid}


wafcrs-id>

PATCH /policy/api/v1/infra/alb-waf- PATCH /api/wafcrs/{uuid}


crs/<alb-wafcrs-id>

PUT /policy/api/v1/infra/alb-waf-crs/<alb- PUT /api/wafcrs/{uuid}


wafcrs-id>

ALB WAF Policies


GET /policy/api/v1/infra/alb-waf-policies GET /api/wafpolicy

DELETE /policy/api/v1/infra/alb-waf- DELETE //apiwafpolicy/{uuid}


policies/<alb-wafpolicy-id>

GET /policy/api/v1/infra/alb-waf- GET /api/wafpolicy/{uuid}


policies/<alb-wafpolicy-id>

PATCH /policy/api/v1/infra/alb-waf- PATCH /api/wafpolicy/{uuid}


policies/<alb-wafpolicy-id>

PUT /policy/api/v1/infra/alb-waf- PUT /api/wafpolicy/{uuid}


policies/<alb-wafpolicy-id>

ALB WAF Policy PSM Groups


GET /policy/api/v1/infra/alb-waf-policy- GET /api/wafpolicypsmgroup
psm-groups

DELETE /policy/api/v1/infra/alb-waf-policy- DELETE /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

GET /policy/api/v1/infra/alb-waf-policy- GET /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

PATCH /policy/api/v1/infra/alb-waf-policy- PATCH /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

PUT /policy/api/v1/infra/alb-waf-policy- PUT /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 16/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB WAF Profiles


GET /policy/api/v1/infra/alb-waf-profiles GET /api/wafprofile

DELETE /policy/api/v1/infra/alb-waf- DELETE /api/wafprofile/{uuid}


profiles/<alb-wafprofile-id>

GET /policy/api/v1/infra/alb-waf- GET /api/wafprofile/{uuid}


profiles/<alb-wafprofile-id>

PATCH /policy/api/v1/infra/alb-waf- PATCH /vwafprofile/{uuid}


profiles/<alb-wafprofile-id>

PUT /policy/api/v1/infra/alb-waf- PUT /wafprofile/{uuid}


profiles/<alb-wafprofile-id>

Advanced Load Balancing Functionality Deprecated API https://{NSX-T-Policy- Recommendation Avi API
Manager-IP/FQDN}/<api>
https://{Avi-controller-IP/FQDN}/<api>

ALB Auth Token PUT /policy/api/v1/infra/alb-auth-token Not Applicable

ALB Controller Version GET /policy/api/v1/infra/alb-controller- GET /api/initial-data


version

ALB Analytics Profile


GET /policy/api/v1/infra/alb-analytics- GET /api/analyticsprofile
profiles

DELETE /policy/api/v1/infra/alb-analytics- GET /api/analyticsprofile


profiles/<alb-analyticsprofile-id>

GET /policy/api/v1/infra/alb-analytics- DELETE


profiles/<alb-analyticsprofile-id> /api/analyticsprofile/{uuid}GET /api/analytic
sprofile/{uuid}

PATCH /policy/api/v1/infra/alb-analytics- PATCH /api/analyticsprofile/{uuid}


profiles/<alb-analyticsprofile-id>

PUT /policy/api/v1/infra/alb-analytics- PUT /api/analyticsprofile/{uuid}


profiles/<alb-analyticsprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 17/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Application Persistence Profiles


GET /policy/api/v1/infra/alb-application- GET /api/applicationpersistenceprofile
persistence-profiles

DELETE /policy/api/v1/infra/alb- DELETE


application-persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

GET /policy/api/v1/infra/alb-application- GET


persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

PATCH /policy/api/v1/infra/alb-application- PATCH


persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

PUT /policy/api/v1/infra/alb-application- PUT


persistence-profiles/<alb- /api/applicationpersistenceprofile/{uuid}
applicationpersistenceprofile-id>

ALB Application Profiles


GET /policy/api/v1/infra/alb-application- GET /api/applicationprofile
profiles

DELETE /policy/api/v1/infra/alb- DELETE /api/applicationprofile/{uuid}


application-profiles/<alb-applicationprofile-
id>

GET /policy/api/v1/infra/alb-application- GET /api/applicationprofile/{uuid}


profiles/<alb-applicationprofile-id>

PATCH /policy/api/v1/infra/alb-application- PATCH /api/applicationprofile/{uuid}


profiles/<alb-applicationprofile-id>

PUT /policy/api/v1/infra/alb-application- PUT /api/applicationprofile/{uuid}


profiles/<alb-applicationprofile-id>

ALB Auth Profiles


GET /policy/api/v1/infra/alb-auth-profiles GET /api/authprofile

DELETE /policy/api/v1/infra/alb-auth- DELETE /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

GET /policy/api/v1/infra/alb-auth- GET /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

PATCH /policy/api/v1/infra/alb-auth- PATCH /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

PUT /policy/api/v1/infra/alb-auth- PUT /api/authprofile/{uuid}


profiles/<alb-authprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 18/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Auto Scale Launch Configs


GET /policy/api/v1/infra/alb-auto-scale- GET /api/autoscalelaunchconfig
launch-configs

DELETE /policy/api/v1/infra/alb-auto-scale- DELETE /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

GET /policy/api/v1/infra/alb-auto-scale- GET /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

PATCH /policy/api/v1/infra/alb-auto-scale- PATCH /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

PUT /policy/api/v1/infra/alb-auto-scale- PUT /api/autoscalelaunchconfig/{uuid}


launch-configs/<alb-
autoscalelaunchconfig-id>

ALB DNS Policies


GET /policy/api/v1/infra/alb-dns-policies GET /api/dnspolicy

DELETE /policy/api/v1/infra/alb-dns- DELETE /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

GET /policy/api/v1/infra/alb-dns- GET /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

PATCH /policy/api/v1/infra/alb-dns- PATCH /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

PUT /policy/api/v1/infra/alb-dns- PUT /api/dnspolicy/{uuid}


policies/<alb-dnspolicy-id>

ALB Error Page Bodies


GET /policy/api/v1/infra/alb-error-page- GET /api/errorpagebody
bodies

DELETE /policy/api/v1/infra/alb-error- DELETE /api/errorpagebody/{uuid}


page-bodies/<alb-errorpagebody-id>

GET /policy/api/v1/infra/alb-error-page- GET /api/errorpagebody/{uuid}


bodies/<alb-errorpagebody-id>

PATCH /policy/api/v1/infra/alb-error-page- PATCH /api/errorpagebody/{uuid}


bodies/<alb-errorpagebody-id>

PUT /policy/api/v1/infra/alb-error-page- PUT /api/errorpagebody/{uuid}


bodies/<alb-errorpagebody-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 19/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Error Page Profiles


GET /policy/api/v1/infra/alb-error-page- GET /api/errorpageprofile
profiles

DELETE /policy/api/v1/infra/alb-error- DELETE /api/errorpageprofile/{uuid}


page-profiles/<alb-errorpageprofile-id>

GET /policy/api/v1/infra/alb-error-page- GET /api/errorpageprofile/{uuid}


profiles/<alb-errorpageprofile-id>

PATCH /policy/api/v1/infra/alb-error-page- PATCH /api/errorpageprofile/{uuid}


profiles/<alb-errorpageprofile-id>

PUT /policy/api/v1/infra/alb-error-page- PUT /api/errorpageprofile/{uuid}


profiles/<alb-errorpageprofile-id>

ALB HTTP Policy Sets


GET /policy/api/v1/infra/alb-http-policy-sets GET /api/httppolicyset

DELETE /policy/api/v1/infra/alb-http-policy- DELETE /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

GET /policy/api/v1/infra/alb-http-policy- GET /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

PATCH /policy/api/v1/infra/alb-http-policy- PATCH /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

PUT /policy/api/v1/infra/alb-http-policy- PUT /api/httppolicyset/{uuid}


sets/<alb-httppolicyset-id>

ALB Hardware Security Module Groups


GET /policy/api/v1/infra/alb-hardware- GET /api/hardwaresecuritymodulegroup
security-module-group

DELETE /policy/api/v1/infra/alb-hardware- DELETE


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

GET /policy/api/v1/infra/alb-hardware- GET


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

PATCH /policy/api/v1/infra/alb-hardware- PATCH


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

PUT /policy/api/v1/infra/alb-hardware- PUT


security-module-groups/<alb- /api/hardwaresecuritymodulegroup/{uuid}
hardwaresecuritymodulegroup-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 20/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Health Monitors


GET /policy/api/v1/infra/alb-health- GET /api/healthmonitor
monitors

DELETE /policy/api/v1/infra/alb-health- DELETE /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

GET /policy/api/v1/infra/alb-health- GET /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

PATCH /policy/api/v1/infra/alb-health- PATCH /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

PUT /policy/api/v1/infra/alb-health- PUT /api/healthmonitor/{uuid}


monitors/<alb-healthmonitor-id>

ALB IP Addr Groups


GET /policy/api/v1/infra/alb-ip-addr-groups GET /api/ipaddrgroup

DELETE /policy/api/v1/infra/alb-ip-addr- DELETE /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

GET /policy/api/v1/infra/alb-ip-addr- GET /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

PATCH /policy/api/v1/infra/alb-ip-addr- PATCH /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

PUT /policy/api/v1/infra/alb-ip-addr- PUT /api/ipaddrgroup/{uuid}


groups/<alb-ipaddrgroup-id>

ALB L4 Policy Sets


GET /policy/api/v1/infra/alb-l4-policy-sets GET /api/l4policyset

DELETE /policy/api/v1/infra/alb-l4-policy- DELETE /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

GET /policy/api/v1/infra/alb-l4-policy- GET /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

PATCH /policy/api/v1/infra/alb-l4-policy- PATCH /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

PUT /policy/api/v1/infra/alb-l4-policy- PUT /api/l4policyset/{uuid}


sets/<alb-l4policyset-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 21/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Network Profiles


GET /policy/api/v1/infra/alb-network- GET /api/networkprofile
profiles

DELETE /policy/api/v1/infra/alb-network- DELETE /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

GET /policy/api/v1/infra/alb-network- GET /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

PATCH /policy/api/v1/infra/alb-network- PATCH /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

PUT /policy/api/v1/infra/alb-network- PUT /api/networkprofile/{uuid}


profiles/<alb-networkprofile-id>

ALB Network Security Policies


GET /policy/api/v1/infra/alb-network- GET /api/networksecuritypolicy
security-policies

DELETE /policy/api/v1/infra/alb-network- DELETE /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

GET /policy/api/v1/infra/alb-network- GET /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

PATCH /policy/api/v1/infra/alb-network- PATCH /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

PUT /policy/api/v1/infra/alb-network- PUT /api/networksecuritypolicy/{uuid}


security-policies/<alb-
networksecuritypolicy-id>

ALB Onboarding Workflow PUT /policy/api/v1/infra/alb-onboarding- Not Applicable.


workflowDELETE /policy/api/v1/infra/alb-
onboarding-workflow/<managed-by>

ALB PKI Profiles


GET /policy/api/v1/infra/alb-pki-profiles GET /api/pkiprofile

DELETE /policy/api/v1/infra/alb-pki- DELETE /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

GET /policy/api/v1/infra/alb-pki- GET /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

PATCH /policy/api/v1/infra/alb-pki- PATCH /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

PUT /policy/api/v1/infra/alb-pki- PUT /api/pkiprofile/{uuid}


profiles/<alb-pkiprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 22/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Pool Group Deployment Policies


GET /policy/api/v1/infra/alb-pool-group- GET /api/poolgroupdeploymentpolicy
deployment-policies

DELETE /policy/api/v1/infra/alb-pool- DELETE


group-deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

GET /policy/api/v1/infra/alb-pool-group- GET


deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

PATCH /policy/api/v1/infra/alb-pool-group- PATCH


deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

PUT /policy/api/v1/infra/alb-pool-group- PUT


deployment-policies/<alb- /api/poolgroupdeploymentpolicy/{uuid}
poolgroupdeploymentpolicy-id>

ALB Pool Groups


GET /policy/api/v1/infra/alb-pool-groups GET /api/poolgroup

DELETE /policy/api/v1/infra/alb-pool- DELETE /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

GET /policy/api/v1/infra/alb-pool- GET /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

PATCH /policy/api/v1/infra/alb-pool- PATCH /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

PUT /policy/api/v1/infra/alb-pool- PUT /api/poolgroup/{uuid}


groups/<alb-poolgroup-id>

ALB Pools
GET /policy/api/v1/infra/alb-pools GET /api/pool

DELETE /policy/api/v1/infra/alb-pools/<alb- DELETE /api/pool/{uuid}


pool-id>

GET /policy/api/v1/infra/alb-pools/<alb- GET /api/pool/{uuid}


pool-id>

PATCH /policy/api/v1/infra/alb-pools/<alb- PATCH /api/pool/{uuid}


pool-id>

PUT /policy/api/v1/infra/alb-pools/<alb- /PUT /api/pool/{uuid}


pool-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 23/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Priority Labels


GET /policy/api/v1/infra/alb-priority-labels GET /api/prioritylabels

DELETE /policy/api/v1/infra/alb-priority- DELETE /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

GET /policy/api/v1/infra/alb-priority- GET /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

PATCH /policy/api/v1/infra/alb-priority- PATCH /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

PUT /policy/api/v1/infra/alb-priority- PUT /api/prioritylabels/{uuid}


labels/<alb-prioritylabels-id>

ALB Protocol Parsers


GET /policy/api/v1/infra/alb-protocol- GET /api/protocolparser
parsers

DELETE /policy/api/v1/infra/alb-protocol- DELETE /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

GET /policy/api/v1/infra/alb-protocol- GET /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

PATCH /policy/api/v1/infra/alb-protocol- PATCH /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

PUT /policy/api/v1/infra/alb-protocol- PUT /api/protocolparser/{uuid}


parsers/<alb-protocolparser-id>

ALB Security Policies


GET /policy/api/v1/infra/alb-security- GET /api/securitypolicy
policies

DELETE /policy/api/v1/infra/alb-security- DELETE /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

GET /policy/api/v1/infra/alb-security- GET /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

PATCH /policy/api/v1/infra/alb-security- PATCH /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

PUT /policy/api/v1/infra/alb-security- PUT /api/securitypolicy/{uuid}


policies/<alb-securitypolicy-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 24/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Server Auto Scale Policies


GET /policy/api/v1/infra/alb-server-auto- GET /api/serverautoscalepolicy
scale-policies

DELETE /policy/api/v1/infra/alb-server- DELETE /api/serverautoscalepolicy/{uuid}


auto-scale-policies/<alb-
serverautoscalepolicy-id>

GET /policy/api/v1/infra/alb-server-auto- GET /api/serverautoscalepolicy/{uuid}


scale-policies/<alb-serverautoscalepolicy-
id>

PATCH /policy/api/v1/infra/alb-server-auto- PATCH /api/serverautoscalepolicy/{uuid}


scale-policies/<alb-serverautoscalepolicy-
id>

PUT /policy/api/v1/infra/alb-server-auto- PUT /api/serverautoscalepolicy/{uuid}


scale-policies/<alb-serverautoscalepolicy-
id>+

ALB SSL Key And Certificates


GET /policy/api/v1/infra/alb-ssl-key-and- GET /api/sslkeyandcertificate
certificates

DELETE /policy/api/v1/infra/alb-ssl-key- DELETE /api/sslkeyandcertificate/{uuid}


and-certificates/<alb-sslkeyandcertificate-
id>

GET /policy/api/v1/infra/alb-ssl-key-and- GET /api/sslkeyandcertificate/{uuid}


certificates/<alb-sslkeyandcertificate-id>

PATCH /policy/api/v1/infra/alb-ssl-key-and- PATCH /api/sslkeyandcertificate/{uuid}


certificates/<alb-sslkeyandcertificate-id>

PUT /policy/api/v1/infra/alb-ssl-key-and- PUT /api/sslkeyandcertificate/{uuid}


certificates/<alb-sslkeyandcertificate-id>

ALB SSL Profiles


GET /policy/api/v1/infra/alb-ssl- GET /api/sslprofile
profilesDELETE /policy/api/v1/infra/alb-ssl-
profiles/<alb-sslprofile-id>

DELETE /policy/api/v1/infra/alb-ssl- DELETE /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

GET /policy/api/v1/infra/alb-ssl- GET /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

PATCH /policy/api/v1/infra/alb-ssl- PATCH /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

PUT /policy/api/v1/infra/alb-ssl- PUT /api/sslprofile/{uuid}


profiles/<alb-sslprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 25/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB SSO Policies


GET /policy/api/v1/infra/alb-sso-policies GET /api/ssopolicy

DELETE /policy/api/v1/infra/alb-sso- DELETE /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

GET /policy/api/v1/infra/alb-sso- GET /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

PATCH /policy/api/v1/infra/alb-sso- PATCH /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

PUT /policy/api/v1/infra/alb-sso- PUT /api/ssopolicy/{uuid}


policies/<alb-ssopolicy-id>

ALB String Groups


GET /policy/api/v1/infra/alb-string-groups GET /api/stringgroup

DELETE /policy/api/v1/infra/alb-string- DELETE /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

GET /policy/api/v1/infra/alb-string- GET /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

PATCH /policy/api/v1/infra/alb-string- PATCH /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

PUT /policy/api/v1/infra/alb-string- PUT /api/stringgroup/{uuid}


groups/<alb-stringgroup-id>

ALB Traffic Clone Profiles


GET /policy/api/v1/infra/alb-traffic-clone- GET /api/trafficcloneprofile
profiles

DELETE /policy/api/v1/infra/alb-traffic- DELETE /api/trafficcloneprofile/{uuid}


clone-profiles/<alb-trafficcloneprofile-id>

GET /policy/api/v1/infra/alb-traffic-clone- GET /api/trafficcloneprofile/{uuid}


profiles/<alb-trafficcloneprofile-id>

PATCH /policy/api/v1/infra/alb-traffic-clone- PATCH /api/trafficcloneprofile/{uuid}


profiles/<alb-trafficcloneprofile-id>

PUT /policy/api/v1/infra/alb-traffic-clone- PUT /api/trafficcloneprofile/{uuid}


profiles/<alb-trafficcloneprofile-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 26/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB Virtual Services


GET /policy/api/v1/infra/alb-virtual-services GET /api/virtualservice

DELETE /policy/api/v1/infra/alb-virtual- DELETE /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

GET /policy/api/v1/infra/alb-virtual- GET /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

PATCH /policy/api/v1/infra/alb-virtual- PATCH /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

PUT /policy/api/v1/infra/alb-virtual- PUT /api/virtualservice/{uuid}


services/<alb-virtualservice-id>

ALB VS Data Script Sets


GET /policy/api/v1/infra/alb-vs-data-script- GET /api/vsdatascriptset
sets

DELETE /policy/api/v1/infra/alb-vs-data- DELETE /api/vsdatascriptset/{uuid}


script-sets/<alb-vsdatascriptset-id>

GET /policy/api/v1/infra/alb-vs-data-script- GET /api/vsdatascriptset/{uuid}


sets/<alb-vsdatascriptset-id>

PATCH /policy/api/v1/infra/alb-vs-data- PATCH /api/vsdatascriptset/{uuid}


script-sets/<alb-vsdatascriptset-id>

PUT /policy/api/v1/infra/alb-vs-data-script- PUT /api/vsdatascriptset/{uuid}


sets/<alb-vsdatascriptset-id>

ALB VS Vips
GET /policy/api/v1/infra/alb-vs-vips GET /api/vsvip

DELETE /policy/api/v1/infra/alb-vs- DELETE /api/vsvip/{uuid}


vips/<alb-vsvip-id>

GET /policy/api/v1/infra/alb-vs-vips/<alb- GET /api/vsvip/{uuid}


vsvip-id>

PATCH /policy/api/v1/infra/alb-vs- PATCH /api/vsvip/{uuid}


vips/<alb-vsvip-id>

PUT /policy/api/v1/infra/alb-vs-vips/<alb- PUT /api/vsvip/{uuid}


vsvip-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 27/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB WAF CRS


GET /policy/api/v1/infra/alb-waf-crs GET /api/wafcrs

DELETE /policy/api/v1/infra/alb-waf- DELETE /api/wafcrs/{uuid}


crs/<alb-wafcrs-id>

GET /policy/api/v1/infra/alb-waf-crs/<alb- GET /api/wafcrs/{uuid}


wafcrs-id>

PATCH /policy/api/v1/infra/alb-waf- PATCH /api/wafcrs/{uuid}


crs/<alb-wafcrs-id>

PUT /policy/api/v1/infra/alb-waf-crs/<alb- PUT /api/wafcrs/{uuid}


wafcrs-id>

ALB WAF Policies


GET /policy/api/v1/infra/alb-waf-policies GET /api/wafpolicy

DELETE /policy/api/v1/infra/alb-waf- DELETE //apiwafpolicy/{uuid}


policies/<alb-wafpolicy-id>

GET /policy/api/v1/infra/alb-waf- GET /api/wafpolicy/{uuid}


policies/<alb-wafpolicy-id>

PATCH /policy/api/v1/infra/alb-waf- PATCH /api/wafpolicy/{uuid}


policies/<alb-wafpolicy-id>

PUT /policy/api/v1/infra/alb-waf- PUT /api/wafpolicy/{uuid}


policies/<alb-wafpolicy-id>

ALB WAF Policy PSM Groups


GET /policy/api/v1/infra/alb-waf-policy- GET /api/wafpolicypsmgroup
psm-groups

DELETE /policy/api/v1/infra/alb-waf-policy- DELETE /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

GET /policy/api/v1/infra/alb-waf-policy- GET /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

PATCH /policy/api/v1/infra/alb-waf-policy- PATCH /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

PUT /policy/api/v1/infra/alb-waf-policy- PUT /api/wafpolicypsmgroup/{uuid}


psm-groups/<alb-wafpolicypsmgroup-id>

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 28/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Deprecated API https://{NSX-T-Policy- Recommendation Avi API


Advanced Load Balancing Functionality
Manager-IP/FQDN}/<api> https://{Avi-controller-IP/FQDN}/<api>

ALB WAF Profiles


GET /policy/api/v1/infra/alb-waf-profiles GET /api/wafprofile

DELETE /policy/api/v1/infra/alb-waf- DELETE /api/wafprofile/{uuid}


profiles/<alb-wafprofile-id>

GET /policy/api/v1/infra/alb-waf- GET /api/wafprofile/{uuid}


profiles/<alb-wafprofile-id>

PATCH /policy/api/v1/infra/alb-waf- PATCH /vwafprofile/{uuid}


profiles/<alb-wafprofile-id>

PUT /policy/api/v1/infra/alb-waf- PUT /wafprofile/{uuid}


profiles/<alb-wafprofile-id>

ALB Webhooks
GET /policy/api/v1/infra/alb-webhooks GET /api/webhook

DELETE /policy/api/v1/infra/alb- DELETE /api/webhook/{uuid}


webhooks/<alb-webhook-id>

GET /policy/api/v1/infra/alb- GET /api/webhook/{uuid}


webhooks/<alb-webhook-id>

PATCH /policy/api/v1/infra/alb- PATCH /api/webhook/{uuid}


webhooks/<alb-webhook-id>

PUT /policy/api/v1/infra/alb- PUT /api/webhook/{uuid}


webhooks/<alb-webhook-id>

ALB Webhooks
GET /policy/api/v1/infra/alb-webhooks GET /api/webhook

DELETE /policy/api/v1/infra/alb- DELETE /api/webhook/{uuid}


webhooks/<alb-webhook-id>

GET /policy/api/v1/infra/alb- GET /api/webhook/{uuid}


webhooks/<alb-webhook-id>

PATCH /policy/api/v1/infra/alb- PATCH /api/webhook/{uuid}


webhooks/<alb-webhook-id>

PUT /policy/api/v1/infra/alb- PUT /api/webhook/{uuid}


webhooks/<alb-webhook-id>

Compatibility and System Requirements


For compatibility and system requirements information, see the VMware Product Interoperability Matrices and the NSX Installation
Guide.

Upgrade Notes for This Release


For instructions about upgrading NSXcomponents, see the NSX Upgrade Guide.
Customers upgrading to this release are recommended to run the NSX Upgrade Evaluation Tool before starting the upgrade process.
The tool is designed to ensure success by checking the health and readiness of your NSX Managers prior to upgrading.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 29/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

API and CLI Resources


See developer.vmware.com to use the NSX Data Center APIs or CLIs for automation.
The API documentation is available from the API Reference tab. The CLI documentation is available from the Documentation tab.

Available Languages
NSX has been localized into multiple languages: English, French, German, Italian, Japanese, Korean, Simplified Chinese, Traditional
Chinese, and Spanish. Because NSX localization utilizes the browser language settings, ensure that your settings match the desired
language.

Document Revision History

Revision Date Edition Changes

02 August 2022 1 Initial edition

05 August 2022 2 Updated What's New - Federation

11 August 2022 3 Updated What's New - Feature Deprecation, Added Italian as an available language

17 August 2022 4 Updated Feature Deprecation

30 August 2022 5 Added Resolved Issue 3004234

08 September 2022 6 Added Known Issue 303847

15 September 2022 7 Added Known Issue 3025104

11 March 2023 8 Added Known Issue 2992759

19 May 2023 9 Added Known Issue 3116294

3 July 2024 10 Added Resolved Issue 3223107

Resolved Issues
Fixed Issue 3223107: When BGP receives a same prefix from multiple neighbors and if the nexthop is also of the same subnet,
then the route keeps flapping and user will see a continuous addition and deletion of the prefix.
Traffic drop for prefixes that are getting continuously added/deleted.
Fixed Issue 3004234: Edge VM to be deleted is not reachable from NSX manager, and deletion is stuck.
Unable to delete the edge VM.
Fixed Issue 2969847: Incorrect DSCP priority.
DSCP priority from a custom QoS profile is not propagated to host when the value is 0, resulting in traffic prioritization issues.
Fixed Issue 2994665: Unable to delete T0 Gateway and its interfaces.
Customer was using troubleshooting API to delete interfaces. This failed because of an incorrect request parameter.
Fixed issue 2964752: Page leak in shared memory setup by dvfilter library for vDPI.
1. When packets needs to be dropped from vDPI, due to internal queue being full or TxRing is full, it drops them via IOCTL provided by
dvfilter library 2. At high rate, IOCTL can fail and lead to page(associated with packets) leak.
3. As number of page leaks increase, temporary or permanent traffic loss will be observed If all pages are leaked, then packets cannot
be sent from vmkernel to VDPI and leads to traffic loss.
Fixed Issue 2964713: Rules with more than 15 ports are allowed to publish only to fail in later stages.
Customer may not know that the rule fails to publish / realize out of this reason.
Fixed Issue 3006369: MPS feature activation fails because of missing license information in platform-licenses configmap.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 30/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

1) Common agent updates the configmap "platform-licenses" on platform install. This contains license information and is a pre-requisite
for reputation service to function correctly.
2) In some instances, common agent fails to update the correct license information and hence, the CrashLoopBackOff errors in
reputation-service.
Fixed Issue 2930824: vRA edges from old setup were probably not cleaned properly. Those edges were causing connectivity
issue because they were not getting populated in vra_input.json.
vRA makes a connection from VCenter and not from NSX-V. So these stale edges had connections made from VCenter. Those were
not getting identified during migration
Fixed Issue 2990847: Cross-site route sync for stretched Tier0 gateway didn't resume when interfaces were re-created after
deleting all the interfaces on the edge nodes of one site.
When Tier0 is stretched to more than one, it establishes sessions over internal routing backplane between Tier0 service router. These
remote IBGP session remains in connect state.
Fixed Issue 2974706: Controller failed to join cluster due to failure in re-sync with replication service upon service restart.
Controller failed to join cluster due to failure in re-sync with replication service upon service restart.
Fixed Issue 2982579: Realization of DFW Rule containing Pure AD Policy Groups fails after upgrade to 3.2.1 , if the DFW Rule
is updated after upgrade.
Realization failure of DFW Rule containing Pure AD Groups.
Fixed issue 2971114: Loss of connection to Edge due to datapath refcount issue.
Loss of connection to the Edge, and the following logs seen in syslog: "PAX: refcount overflow detected" "PAX: refcount error occurred
at: scsi_sanitize_inquiry_string+0xc4/0x106 [smartpqi]".
Fixed Issue 2966254: The edge dp coredump is seen when both control prior and service core are enabled.
Fixed Issue 2961029: NSX Manager upgrade retry operation shrinks corfu database and keep it in same state even after
successful upgrade.
Corfu database is in shrink state even after successful upgrade.
Fixed Issue 2958808: PSOD was observed in the process of changing IPFIX configuration.
The host will not be responsive after PSOD.
Fixed Issue 2958765: Handle non-existing cluster gracefully.
When policy API enables or disables IDFW on a non-existing cluster, a null pointer error will occur. This needs to be handled gracefully.
Fixed Issue 2958252: VDS IPFIX does not function with NSX installed.
Collector does not receive correctly sampled flows by VDS IPFIX.
Fixed Issue 2957476: Out of order packets incoming to nsx-idps are silently dropped.
Out of order packets incoming to nsx-idps are silently dropped, resulting in drop count per profile incrementing.
Fixed Issue 2954926: PSOD after vMotion of VMs in an environment with sink port (primarily HCX environment) connected to
vSphere DVPG and MAC learning enabled ports in the same DVS (either from NSX or vSphere).
Fixed Issue 2951440: MP MTU value set by the user was overwritten by PolicyDefault MTU value of 1500 on upgrade and
restart of the policy manager.
Post Upgrade Service Uplink MTU settings are not getting applied to the CGW segments.
Fixed Issue 2950628: NSX manager loses connectivity with ESXi host after host upgrade.
After multi-hop upgrade of ESXi host from 6.7 u3 --> 7.0 u3c--> 7.0 u3d,the host is not responding and connectivity with NSX manager
is lost. If we try to create vmk port then we get following error: "unable to add vmkernel network interface: Error was: unable to get node:
not implemented"
Fixed Issue 2949077: Certificate pre-check is failing during upgrade.
During pre-check a list of certificates are marked invalid and need to be replaced
Fixed Issue 2946392: The hanging nslookup command blocked FQDN lookup metrics collector in SHA.
FQDN lookup metrics collector in SHA executed nslookup command to collect info. It was blocked to wait for the hanging command.
The former FQDN lookup alarm hadn't been removed till the hanging commands terminated.
Fixed Issue 2937814: NSX API call fails to return overlay_id (VNI).
There is an "Unable to find layer 2 id for segment" error. Unable to extend the L2 network.
Fixed Issue: 2932465: Password printed in log.
auth_password and priv_password printed in log.
Fixed Issue 2928071: Force delete on the host does not work once the host and manager connection is down.
The host remains in the manager DB and the user is unable to remove it.
Fixed Issue 2921515: Random traffic interruption due to dvfilter channel lockup.
The dvfilter communication channel between kernel and userspace gets stuck after running traffic for some time. The result is that
packets cannot be sent out afterwards.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 31/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Fixed Issue 2880193: DHCP relay failing to provide IPv6 addresses from DHCPv6 server.
Fixed Issue 2966210: Message of the day in CLI is not accepting special characters.
Customer was trying to set the motd (message of the day) with a special character. It was showing the below error.API [ PUT
https://<nsx-mgr>/api/v1/node ] ("error_code": 36102, "error_message": "Error setting message of the day.", "module_name": "node-
services”).
Fixed Issue: 2957417: MP UI is not showing the correct route-map with AS-PATH prepend format of because of Model to Dto
conversion.
MP UI is not showing the correct route-map with AS-PATH prepend format. It is not showing to AS PLAIN or DOTTED format.
Fixed Issue 2946589: ESXi hosts reported "UNKNOWN" state in NSX and VMs lost networking.
1. ESXi Host reported "UNKNOWN" status in NSX UI (NSX controller status showed not available)
2. VMs lost networking after migrating to this host
3. VMs ports could be in a blocked state
Fixed Issue 2937981: NSX reinstallation on ESXi stops at 96%.
The transport node realization progress on the UI shows 96%. The deployment_progress_state through the transport node state API
reflects this as well.
Fixed Issue 2932398: If a trunk segment has a large VLAN range and is attached to a VRF access port, the trunk logical router
port on T0 fails to get realized die to VLAN conflict.
If a trunk segment has a large VLAN ranges and is attached to a VRF’s access port, the trunk logical router port on T0 is failed to be
realized due to VLAN conflict. T0 is then stuck in failed status. Later the deletion of VRF still fails to delete the realization entity of the
trunk logical router port due to a timing issue. This causes that T0 stuck in failed status.
Fixed Issue 2920857: TCP MSS of SYN packets leaving T0 uplinks is not being correctly calculated from interface MTU.
PMTU is forwarded to the Linux properly but mss is not changed due to the asymmetric forwarding path on the Linux side. The ICMP
error message (mtu too big) is not forwarded to the Linux kernel.
Fixed Issue 2914689: When there is an exception during host unprep, host remains in an uninstalling state.
The host remains in uninstalling state on the UI. DB record updating also does not happen.
Fixed Issue 2852146: When both the access token and the refresh token are expired at the same time when using vIDM, the
first request will fail with a 403 error even with correct credentials.
After the refresh token expires, attempting to create a new session will first be met with a 403 error. Subsequent attempts will succeed.
Fixed Issue 2879979: IKE service may not initiate new IPsec route based session after "dead peer detection" has happened
due to IPsec peer being unreachable.
There could be outage for specific IPsec route based session.
Fixed Issue 2879734: Configuration fails when same self signed certificate is used in two different IPsec local endpoints.
"Configuration failed" error is seen for the second IPsec session using the same self signed certificate
Fixed Issue 2816781: Physical servers cannot be configured with a load-balancing based teaming policy as they support a
single VTEP.
TransportNode installation will go in a failure state. You won't be able to configure physical servers with a load-balancing based teaming
policy.
Fixed Issue 2879119: When a virtual router is added, the corresponding kernel network interface does not come up.
Routing on the vrf fails. No connectivity is established for VMs connected through the vrf.
Fixed Issue 2874995: LCores priority may remain high even when not used, rendering them unusable by some VMs.
Performance degradation for "Normal Latency" VMs.
Fixed Issue 2854139: Continuous addition/removal of BGP routes into RIB for a topology where Tier0 SR on edge has multiple
BGP neighbors and these BGP neighbors are sending ECMP prefixes to the Tier0 SR.
Traffic drop for the prefixes that are getting continuously added/deleted.
Fixed Issue 2839782: Unable to upgrade from NSX-T 2.4.1 to 2.5.1 because CRL entity is large, and Corfu imposes a size limit
in 2.4.1, thereby preventing the CRL entity from being created in the Corfu during upgrade.
Unable to upgrade.
Fixed Issue 2561988: All IKE/IPSEC sessions are temporarily disrupted.
Traffic outage will be seen for some time.
Fixed Issue 2945515: NSX tools upgrade in Azure can fail on Redhat Linux VMs.
By default, NSX tools are installed on /opt directory. However, during NSX tools installation default path can be overridden with "--
chroot-path" option passed to the install script.
Insufficient disk space on the partition where NSX tools is installed can cause NSX tools upgrade to fail.

Known Issues
https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 32/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Issue 3116294: Rule with nested group does not work as expected on hosts.
Traffic not allowed or skipped correctly.
Workaround: See knowledge base article 91421.
Issue 2992759: Prechecks fail during NSX Application Platform 4.0.1 deployment on NSX-T versions 3.2.0/3.2.1/4.0.0.1 with
upstream K8s v1.24.
The prechecks fail with the following error message:
"Kubernetes cluster must have minimum 1 ready master node(s)."
None.
Issue 3025104: Host showing "Failed " state when restore performed on different IP and same FQDN
When restore is performed using different IP of MP nodes using the same FQDN, hosts are not able to connect to the MP nodes.
Workaround: Refresh DNS cache for the host. Use command /etc/init.d/nscd restart.
Issue 3030847: Changes in VRF BGP config don't always take effect.
1. Edit any parameter inside VRF BGP config, such as ecmp or aggregate-routes.
2. Check FRR config on edge, or use BGP CLI and can see that the config did not go into effect.
This issue is not consistently reproducible because if there is any other config change happening concurrently, then we will not see this
problem.
Workaround: Create a dummy static route and remove it. This will cause a configuration push which will realize the VRF BGP config on
the edge.
Issue 3005685: When configuring an Open ID Connect connection as an NSX LM authentication provider, customers may
encounter errors.
OpenID Connect configuration produces errors on configuration.
Workaround: None.
Issue 2663483: The single-node NSX Manager will disconnect from the rest of the NSX Federation environment if you replace
the APH-AR certificate on that NSX Manager.
This issue is seen only with NSX Federation and with the single node NSX Manager Cluster. The single-node NSX Manager will
disconnect from the rest of the NSX Federation environment if you replace the APH-AR certificate on that NSX Manager.
Workaround: Single-node NSX Manager cluster deployment is not a supported deployment option, so have three-node NSX Manager
cluster.
Issue 2879133: Malware Prevention feature can take up to 15 minutes to start working.
When the Malware Prevention feature is configured for the first time, it can take up to 15 minutes for the feature to be initialized. During
this initialization, no malware analysis will be done, but there is no indication that the initialization is occurring.
Workaround: Wait 15 minutes.
Issue 2868944: UI feedback is not shown when migrating more than 1,000 DFW rules from NSX for vSphere to NSX-T Data
Center, but sections are subdivided into sections of 1,000 rules or fewer.
UI feedback is not shown.
Workaround: Check the logs.
Issue 2865273: Advanced Load Balancer (Avi) search engine won't connect to Avi Controller if there is a DFW rule to block
ports 22, 443, 8443 and 123 prior to migration from NSX for vSphere to NSX-T Data Center.
Avi search engine is not able to connect to the Avi Controller.
Workaround: Add explicit DFW rules to allow ports 22, 443, 8443 and 123 for SE VMs or exclude SE VMs from DFW rules.
Issue 2864929: Pool member count is higher when migrated from NSX for vSphere to Avi Load Balancer on NSX-T Data
Center.
You will see a higher pool member count. Health monitor will mark those pool members down but traffic won't be sent to unreachable
pool members.
Workaround: None.
Issue 2719682: Computed fields from Avi controller are not synced to intent on Policy resulting in discrepancies in Data
shown on Avi UI and NSX-T UI.
Computed fields from Avi controller are shown as blank on the NSX-T UI.
Workaround: App switcher to be used to check the data from Avi UI.
Issue 2848614: When joining an MP to an MP cluster where publish_fqdns is set on the MP cluster and where the forward or
reverse lookup entry missing in external DNS server or dns entry missing for joining node, forward or reverse alarms are not
generated for the joining node.
Forward/Reverse alarms are not generated for the joining node even though forward/reverse lookup entry is missing in DNS server or
dns entry is missing for the joining node.
Workaround: Configure the external DNS server for all Manager nodes with forward and reverse DNS entries.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 33/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Issue 2871585: Removal of host from DVS and DVS deletion is allowed for DVS versions less than 7.0.3 after NSX Security on
vSphere DVPortgroups feature is enabled on the clusters using the DVS.
You may have to resolve any issues in transport node or cluster configuration that arise from a host being removed from DVS or DVS
deletion.
Workaround: None.
Issue 2870085: Security policy level logging to enable/disable logging for all rules is not working.
You will not be able to change the logging of all rules by changing "logging_enabled" of security policy.
Workaround: Modify each rule to enable/disable logging.
Issue 2866682: In Microsoft Azure, when accelerated networking is enabled on SUSE Linux Enterprise Server (SLES) 12 SP4
Workload VMs and with NSX Agent installed, the ethernet interface does not obtain an IP address.
VM agent doesn't start and VM becomes unmanaged.
Workaround: Disable Accelerated networking.
Issue 2884939: NSX-T Policy API results in error: Client 'admin' exceeded request rate of 100 per second (Error code: 102).
The NSX rate limiting of 100 requests per second is reached when we migrate a large number of VS from NSX for vSphere to NSX-T
ALB and all APIs are temporarily blocked.
Workaround: Update Client API rate limit to 200 or more requests per second.
Note: There is fix on AVI version 21.1.4 release.
Issue 2792485: NSX manager IP is shown instead of FQDN for manager installed in vCenter.
NSX-T UI Integrated in vCenter shows NSX manager IP instead of FQDN for installed manager.
Workaround: None.
Issue 2888207: Unable to reset local user credentials when vIDM is enabled.
You are unable to change local user passwords while vIDM is enabled.
Workaround: vIDM configuration must be (temporarily) disabled, the local credentials reset during this time, and then integration re-
enabled.
Issue 2885330: Effective member not shown for AD group.
Effective members of AD group not displayed. No datapath impact.
Workaround: None.
Issue 2877776: "get controllers" output may show stale information about controllers that are not the master when compared
to the controller-info.xml file.
This CLI output is confusing.
Workaround: Restart nsx-proxy on that TN.
Issue 2853889: When creating EVPN Tenant Config (with vlan-vni mapping), Child Segments are created, but the child
segment's realization status gets into failed state for about 5 minutes and recovers automatically.
It will take 5 minutes to realize the EVPN tenant configuration.
Workaround: None. Wait 5 minutes.
Issue 2690457: When joining an MP to an MP cluster where publish_fqdns is set on the MP cluster and where the external DNS
server is not configured properly, the proton service may not restart properly on the joining node.
The joining manager will not work and the UI will not be available.
Workaround: Configure the external DNS server with forward and reverse DNS entries for all Manager nodes.
Issue 2490064: Attempting to disable VMware Identity Manager with "External LB" toggled on does not work.
After enabling VMware Identity Manager integration on NSX with "External LB", if you attempt to then disable integration by switching
"External LB" off, after about a minute, the initial configuration will reappear and overwrite local changes.
Workaround: When attempting to disable vIDM, do not toggle the External LB flag off; only toggle off vIDM Integration. This will cause
that config to be saved to the database and synced to the other nodes.
Issue 2355113: Workload VMs running RedHat and CentOS on Azure accelerated networking instances is not supported.
In Azure when accelerated networking is enabled on RedHat or CentOS based OS's and with NSX Agent installed the ethernet interface
does not obtain an IP address.
Workaround: Disable accelerated networking for RedHat and CentOS based OS.
Issue 2684574: If the edge has 6K+ routes for Database and Routes, the Policy API times out.
These Policy APIs for the OSPF database and OSPF routes return an error if the edge has 6K+ routes: /tier-0s/<tier-0s-id>/locale-
services/<locale-service-id>/ospf/routes /tier-0s/<tier-0s-id>/locale-services/<locale-service-id>/ospf/routes?format=csv /tier-0s/<tier-0s-
id>/locale-services/<locale-service-id>/ospf/database /tier-0s/<tier-0s-id>/locale-services/<locale-service-id>/ospf/database?format=csv
If the edge has 6K+ routes for Database and Routes, the Policy API times out. This is a read-only API and has an impact only if the
API/UI is used to download 6k+ routes for OSPF routes and database.
Workaround: Use the CLI commands to retrieve the information from the edge.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 34/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Issue 2574281: Policy will only allow a maximum of 500 VPN Sessions.
NSX claims support of 512 VPN Sessions per edge in the large form factor, however, due to Policy doing auto plumbing of security
policies, Policy will only allow a maximum of 500 VPN Sessions. Upon configuring the 501st VPN session on Tier0, the following error
message is shown: {'httpStatus': 'BAD_REQUEST', 'error_code': 500230, 'module_name': 'Policy', 'error_message': 'GatewayPolicy
path=[/infra/domains/default/gateway-policies/VPN_SYSTEM_GATEWAY_POLICY] has more than 1,000 allowed rules per Gateway
path=[/infra/tier-0s/inc_1_tier_0_1].'}
Workaround: Use Management Plane APIs to create additional VPN Sessions.
Issue 2838613: For ESX version less than 7.0.3, NSX security functionality not enabled on VDS upgraded from version 6.5 to a
higher version after security installation on the cluster.
NSX security features are not enabled on the the VMs connected to VDS upgraded from 6.5 to a higher version (6.6+) where NSX
Security on vSphere DVPortgroups feature is supported.
Workaround: After VDS is upgraded, reboot the host and power on the VMs to enable security on the VMs.
Issue 2799371: IPSec alarms for L2 VPN are not cleared even though L2 VPN and IPSec sessions are up.
No functional impact except that unnecessary open alarms are seen.
Workaround: Resolve alarms manually.
Issue 2584648: Switching primary for T0/T1 gateway affects northbound connectivity.
Location failover time causes disruption for a few seconds and may affect location failover or failback test.
Workaround: None.
Issue 2491800: AR channel SSL certificates are not periodically checked for their validity, which could lead to using an
expired/revoked certificate for an existing connection.
The connection would be using an expired/revoked SSL.
Workaround: Restart the APH on the Manager node to trigger a reconnection.
Issue 2558576: Global Manager and Local Manager versions of a global profile definition can differ and might have an
unknown behavior on Local Manager.
Global DNS, session, or flood profiles created on Global Manager cannot be applied to a local group from UI, but can be applied from
API. Hence, an API user can accidentally create profile binding maps and modify global entity on Local Manager.
Workaround: Use the UI to configure system.
Issue 2950206: CSM is not accessible after MPs are upgraded and before CSM upgrade.
When MP is upgraded, the CSM appliance is not accessible from the UI until the CSM appliance is upgraded completely. NSX services
on CSM are down at this time. It's a temporary state where CSM is inaccessible during an upgrade. The impact is minimal.
Workaround: This is an expected behavior. You have to upgrade the CSM appliance to access CSM UI and ensure all services are
running.
Issue 2882154: Some of the pods are not listed in the output of "kubectl top pods -n nsxi-platform".
The output of "kubectl top pods -n nsxi-platform" will not list all pods for debugging. This does not affect deployment or normal
operation. For certain issues, debugging may be affected. There is no functional impact. Only debugging might be affected.
Workaround: There are two workarounds:
Workaround 1: Make sure the Kubernetes cluster comes up with version 0.4.x of the metrics-server pod before deploying NAPP
platform. This issue is not seen when metrics-server 0.4.x is deployed.
Workaround 2: Delete the metrics-server instance deployed by the NAPP charts and deploy upstream Kubernetes metrics-server
0.4.x.
Issue 2871440: Workloads secured with NSX Security on vSphere dvPortGroups lose their security settings when they are
vMotioned to a host connected to an NSX Manager that is down.
For clusters installed with the NSX Security on vSphere dvPortGroups feature, VMs that are vMotioned to hosts connected to a downed
NSX Manager do not have their DFW and security rules enforced. These security settings are re-enforced when connectivity to NSX
Manager is re-established.
Workaround: Avoid vMotion to affected hosts when NSX Manager is down. If other NSX Manager nodes are functioning, vMotion the
VM to another host that is connected to a healthy NSX Manager.
Issue 2898020: The error 'FRR config failed:: ROUTING_CONFIG_ERROR (-1)' is displayed on the status of transport nodes.
The edge node rejects a route-map sequence configured with a deny action that has more than one community list attached to its
match criteria. If the edge nodes do not have the admin intended configuration, it results in unexpected behavior.
Workaround: None
Issue 2910529: Edge loses IPv4 address after DHCP allocation.
After the Edge VM is installed and received an IP from DHCP server, within a short time it loses the IP address and becomes
inaccessible. This is because the DHCP server does not provide a gateway, hence the Edge node loses IP.
Workaround: Ensure that the DHCP server provides the proper gateway address. If not, perform the following steps:
1. Log in to the console of Edge VM as an admin.
2. Stop service dataplane.

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 35/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

3. Set interface <mgmt intf> dhcp plane mgmt.


4. Start service dataplane.
Issue 2942900: The identity firewall does not work for event log scraping when Active Directory queries time out.
The identity firewall issues a recursive Active Directory query to obtain the user's group information. Active Directory queries can time
out with a NamingException 'LDAP response read timed out, timeout used: 60000 ms'. Therefore, firewall rules are not populated with
event log scraper IP addresses.
Workaround: To improve recursive query times, Active Directory admins may organize and index the AD objects.
Issue 2958032: If you are using NSX-T 3.2 or upgrading to an NSX-T 3.2 maintenance release, the file type is not shown
properly and is truncated at 12 characters on the Malware Prevention dashboard.
On the Malware Prevention dashboard, when you click to see the details of the inspected file, you will see incorrect data because the
file type will be truncated at 12 characters. For example, for a file with File Type as WindowsExecutableLLAppBundleTarArchiveFile, you
will only see WindowsExecu as File Type on Malware Prevention UI.
Workaround: Do a fresh NAPP installation with an NSX-T 3.2 maintenance build instead of upgrading from NSX-T 3.2 to an NSX-T 3.2
maintenance release.
Issue 2954520: When Segment is created from policy and Bridge is configured from MP, detach bridging option is not
available on that Segment from UI.
You will not be able to detach or update bridging from UI if Segment is created from policy and Bridge is configured from MP.
If a Segment is created from the policy side, you are advised to configure bridging only from the policy side. Similarly, if a Logical Switch
is created from the MP side, you should configure bridging only from the MP side.
Workaround: You need to use APIs to remove bridging:
1. Update concerned LogicalPort and remove attachment
PUT :: https://<mgr-ip>/api/v1/logical-ports/<logical-port-id> Add this to headers in PUT payload headers field -> X-Allow-Overwrite :
true
2. DELETE BridgeEndpoint
DELETE :: https://<mgr-ip>/api/v1/bridge-endpoints/<bridge-endpoint-id>
3. Delete LogicalPort
DELETE :: https://<mgr-ip>/api/v1/logical-ports/<logical-port-id>
Issue 2889482: The wrong save confirmation is shown when updating segment profiles for discovered ports.
The Policy UI allows editing of discovered ports but does not send the updated binding map for port update requests when segment
profiles are updated. A false positive message is displayed after clicking Save. Segments appear to be updated for discovered ports, but
they are not.
Workaround: Use MP API or UI to update the segment profiles for discovered ports.
Issue 2919218: Selections made to the host migration are reset to default values after the MC service restarts.
After the restart of the MC service, all the selections relevant to host migration such as enabling or disabling clusters, migration mode,
cluster migration ordering, etc., that were made earlier are reset to default values.
Workaround: Ensure that all the selections relevant to host migration are performed again after the restart of the MC service.
Issue 2931403: Network interface validation prevents API users from performing updates.
An Edge VM network interface can be configured with network resources such as port groups, VLAN logical switches, or segments that
are accessible for specified compute and storage resources. Compute-Id regroup moref in intent is stale and no longer present in VC
after a power outage (moref of resource pool changed after VC was restored).
Workaround: Redeploy edge and specify valid moref Ids.

Content feedback and comments

Products

Solutions

Support and Services

Company

How To Buy

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 36/37
6/1/25, 3:37 PM VMware NSX 4.0.0.1 Release Notes

Copyright © 2005-2025 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.

Privacy Supplier Responsibility Terms of Use Sitemap

  

https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-0/release-notes/vmware-nsx-4001-release-notes.html 37/37

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy