Symptom
The vCenter upgrade precheck reported an IPFIX/NetFlow error for an uplink distributed port group.
“Some uplink distributed portgroup(s) on the source vCenter Server have NetFlow enabled”
“Make sure NetFlow is disabled and NetFlow Override port policies is disabled in the following uplink distributed portgroup(s)”
Diagnostic query
Run the following read-only query on the source vCenter Server:
/opt/vmware/vpostgres/current/bin/psql -U postgres -d VCDB -h localhost -c "SELECT dvpg.dvportgroup_name, dvpg.id AS dvportgroup_id, dvpg.policy_ipfix_override, dvport.dvportgroup_id, dvport.ipfix_enabled, dvport.ipfix_object_flg, CASE WHEN dvport.ipfix_enabled = 1 THEN 'ipfix_enabled = 1' WHEN dvport.ipfix_object_flg IS NULL THEN 'ipfix_object_flg IS NULL' WHEN dvpg.policy_ipfix_override = 1 THEN 'policy_ipfix_override = 1' END AS match_reason FROM VPX_DVPORT_SETTING dvport JOIN VPX_DVPORTGROUP dvpg ON dvport.dvportgroup_id = dvpg.id WHERE dvpg.dvportgroup_name = 'dvSwitch0-DVUplinks-21' AND (dvport.ipfix_enabled = 1 OR dvport.ipfix_object_flg IS NULL OR dvpg.policy_ipfix_override = 1);"
Interpretation
The query checks for any of these conditions:
dvport.ipfix_enabled = 1
dvport.ipfix_object_flg IS NULL
dvpg.policy_ipfix_override = 1
A returned row indicates that the port group may block the upgrade precheck.
In this case, the result was effectively:
policy_ipfix_override | ipfix_enabled | ipfix_object_flg | match_reason
----------------------+---------------+------------------+----------------------
0 | NULL | NULL | ipfix_object_flg IS NULL
This showed that NetFlow was not actively enabled and the override policy was disabled, but stale/incomplete IPFIX metadata remained. The precheck treats a NULL ipfix_object_flg as a failure.
Remediation
On the source vCenter:
- Open the affected distributed port group in the vSphere Client.
- Temporarily enable NetFlow/IPFIX and save the configuration.
- Disable NetFlow/IPFIX again and save the configuration.
- Confirm that the NetFlow override policy is disabled.
This forces vCenter to rewrite the IPFIX metadata. Do not modify the PostgreSQL tables directly.
Verification
Run the same query again:
/opt/vmware/vpostgres/current/bin/psql -U postgres -d VCDB -h localhost -c "SELECT dvpg.dvportgroup_name, dvpg.id AS dvportgroup_id, dvpg.policy_ipfix_override, dvport.dvportgroup_id, dvport.ipfix_enabled, dvport.ipfix_object_flg, CASE WHEN dvport.ipfix_enabled = 1 THEN 'ipfix_enabled = 1' WHEN dvport.ipfix_object_flg IS NULL THEN 'ipfix_object_flg IS NULL' WHEN dvpg.policy_ipfix_override = 1 THEN 'policy_ipfix_override = 1' END AS match_reason FROM VPX_DVPORT_SETTING dvport JOIN VPX_DVPORTGROUP dvpg ON dvport.dvportgroup_id = dvpg.id WHERE dvpg.dvportgroup_name = 'dvSwitch0-DVUplinks-21' AND (dvport.ipfix_enabled = 1 OR dvport.ipfix_object_flg IS NULL OR dvpg.policy_ipfix_override = 1);"
Expected result:
(0 rows)
Once the query returns zero rows, rerun the vCenter upgrade precheck.
Conclusion
The upgrade failure was caused by stale/incomplete IPFIX metadata. Re-saving the NetFlow configuration by enabling and then disabling it corrected the metadata and cleared the precheck condition.