With NSX Distributed Firewall, it is possible to add a "Tag" value to rules.
The Tag column is not displayed by default on the NSX Firewall page.
From the Flash client, select the "Column" icon to the top of the rule table, and checking the "Tag" box.
If you are using the new HTML5 client, you can view the tag by clicking the "Advanced Settings" option on the right hand side of the rule.


I
f a rule that has a "Tag" value assigned is applied to the Edge Service Gateway (shown in the Applied To column), then after upgrading to NSX for vSphere 6.3.3, publishing rules will fail returning the error.