Cisco Virtual Security Gateway for Nexus 1000V Series Switch Troubleshooting Guide, Release 4.2(1)VSG1(3.1)
Troubleshooting Installation Issues
Downloads: This chapterpdf (PDF - 167.0 KB) The complete bookPDF (PDF - 1.02 MB) | The complete bookePub (ePub - 185.0 KB) | The complete bookMobi (Mobi - 274.0 KB) | Feedback

Table of Contents

Troubleshooting Installation Issues

Verifying the VMware License Version

Verifying Port Group Assignments for a Cisco VSG VM Virtual Interface

OVA Installation Behavior

Troubleshooting Installation Issues

This chapter describes how to troubleshoot installation issues for the Cisco Virtual Security Gateway (VSG).

This chapter includes the following sections:

Verifying the VMware License Version

Before beginning to troubleshoot any installation issues, use this procedure to verify that your ESX server has the VMware Enterprise Plus license that includes the Distributed Virtual Switch feature.


Before beginning, you must know or do the following:

  • Log in to the vSphere client where the Cisco VSG will be installed on the ESX server.
  • Log in to the Cisco VSG CLI in EXEC mode.
  • If your vSphere ESX server does not have the Enterprise Plus license, you must upgrade your license.


Step 1 From the vSphere client, choose the host whose Enterprise Plus license that you want to check.

Step 2 Click the Configuration tab and choose Licensed Features.

The Enterprise Plus licensed features appear. See Figure 3-1.

Figure 3-1 Verification of License


Step 3 Verify that the following are included in the Licensed Features:

  • Enterprise Plus license
  • Distributed Virtual Switch feature

Step 4 Do one of the following:

  • If the ESX server has an Enterprise Plus license, you do not have to do anything because the Cisco VSG is available to you.
  • If the ESX server does not have an Enterprise Plus license, upgrade the VMware License to an Enterprise Plus license so that you can see the Cisco VSG.


Verifying Port Group Assignments for a Cisco VSG VM Virtual Interface

Create the following port profiles on the VSM:

  • Data interface port profile (VLAN is the data VLAN)
  • HA interface port profile (VLAN is the HA VLAN)
  • Management port profile (VLAN is the management VLAN)

Ensure that the port groups are assigned to the three virtual interfaces of the Cisco VSG VM in the following order:

1. Network adapter 1 for the data port group

2. Network adapter 2 for the management port group

3. Network adapter 3 for the HA port group

The Cisco VSG VM network adapter 1, network adapter 2, and network adapter 3 are carrying the data VLAN, the HA VLAN, and the management VLAN respectively.

OVA Installation Behavior

During OVA installation, the following error message might appear:

"The network card VirtualE1000 has dvPort backing, which is not supported. This could be because the host does not support vDS, or because the host is not using vDS."

To work around this error, ensure that all three network interfaces in the Cisco VSG port profile are set to the VM Network (port profile from vSwitch) during OVA installation.

Once the virtual machine is created, the port profile for the three interfaces should be changed according to the Cisco Virtual Security Gateway, Release 4.2(1)VSG1(3.1) and Cisco Virtual Network Management Center, Release 1.3 Installation and Upgrade Guide.