This is a known issue impacting NSXe deployments.
Workaround:
During NSX install on the Distributed switch and creation of firewall rules step, we need to add the vCenter and NSX-T manager(s) to the DFW exclusion list using the following process in the NSX-T UI:
- Under Inventory - Tags, create a new tag, for example called 'NSXe_Sytem_VM_Tag' and add both vCenter and NSX manager VMs to it.
- Under Inventory - Groups, create a new group, for example called 'NSXe_System_VM_Group'.
- For the new group, Set Members - Membership Criteria - Virtual Machine - Tag - Equals - NSXe_System_VM_Tag
- Under Security - Distributed Firewall - Actions - Exclusion List , add the created group to exclusion list.
Then proceed to Firewall creation step in NSXe UI security workflow.