This is a known issue affecting VMware NSX for vSphere 6.4.x.
Currently, there is no resolution.
Workaround:
To work around this issue:
- Change the definition of the SGs containing all such VMs which are configured by multiple ip addresses, by splitting/segregating it into smaller SGs.
- The firewall rules, in which the older SGs were consumed, need to be modified to consume the newly created smaller SGs.
To recover from this issue:
Once the system is restarted (automatically, after the issue is hit), delete the SGs containing all such VMs which are configured by multiple ip addresses and then follow the workaround steps.
Note: These virtual machines will not be secured at this time. When this issue is encountered, the security of these virtual machines are lost until a recovery is done.