VMware NSX discovers the IP address bindings associated with VMs. It can learn this information from VMware Tools, ARP Snooping or DHCP Snooping. After the binding discovery, this information inputs into the Realized Bindings. The Realized Binding IP information is used to implement the IP firewall at the dataplane level. In a scaled environment, it is possible there may be a delay in learning Realized Bindings as the VM initializes on the destination host following a vMotion.
This delay may result briefly in incomplete address sets at the ESX dataplane level and consequently a rule not matching as expected.
This is a condition that may occur in a VMware NSX environment.
Workaround:
ARP Snooping by default uses TOFU. Once a binding is realized then it is permanently retained.