-
You have DFW rules created on the "Partner Services" section which contain multiple services under a single rule.
-
You restart the the vShield-Stateful-Firewall service, and now firewall publish tasks succeed.
-
You see error messages similar to the following:
vmkernel.log
2018-04-12T18:39:14.262Z cpu4:8432502)WARNING: Heap: 3867: Could not allocate 299008 bytes for dynamic heap vsiHeap.8432502. Request returned Admission check failed for memory resource
2018-04-12T18:39:34.282Z cpu4:8498110)WARNING: Heap: 3867: Could not allocate 4096 bytes for dynamic heap worldGroup.8498111. Request returned Admission check failed for memory resource
2018-04-12T18:39:34.282Z cpu4:8498110)WARNING: Heap: 3867: Could not allocate 4096 bytes for dynamic heap worldGroup.8498111. Request returned Admission check failed for memory resource
vsm.log
2018-06-07 16:08:51.859 CDT INFO taskScheduler-10 EventBsdFtrMgrImpl:284 - Transactionally updated resource: host-XXXXX, with feature status: [resourceId : null, featureId : com.vmware.vshield.firewall, featureVersion : 5.5, status : YELLOW, installed : true, errorStatus : ]
2018-06-07 16:08:51.893 CDT INFO taskScheduler-10 EventBsdFtrMgrImpl:284 - Transactionally updated resource: host-XXXXX, with feature status: [resourceId : null, featureId : com.vmware.vshield.firewall, featureVersion : 5.5, status : YELLOW, installed : true, errorStatus : ]