> Source: [sk109460](https://support.checkpoint.com/results/sk/sk109460)

# sk109460 - Traffic is not steered to vSEC Gateway for NSX if Virtual Machines are not running VMware Tools

| Property | Value |
|----------|-------|
| Solution ID | sk109460 |
| Date Created | 2016-01-04 |
| Last Modified | 2017-07-13 |
| Technical Level | Advanced |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |
| Platform | VMWare ESX |

## Symptoms

- Traffic is not steered to vSEC Gateway for NSX if Virtual Machines are not running VMware Tools:

* Only Virtual Machines running VMware Tools are inspected properly.
* Traffic from Virtual Machines not running VMware Tools is not inspected by vSEC Gateway, although it is redirected according to VMWare NSX.
* There are no logs relating to inspection of traffic from Virtual Machines not running VMware Tools.

## Cause

NSX Manager cannot properly redirect workloads involving Virtual Machines that are not running VMware Tools.

NSX Manager relies on VMware Tools being installed on each guest Virtual Machine to obtain the Guest IP address.

Redirection of traffic from (or to) a specific Virtual Machine to vSEC Gateway for NSX, or any other service, requires NSX to map the IP address for that specific Virtual Machine.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
