Symptoms:
2021-03-25T16:24:47.196Z INFO FullSyncMsgLoader FirewallSectionFullSyncMessageProvider - FIREWALL [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] Firewall is disabled for LogicalRouter b955628f-####-####-####-########aaa associated to this section FirewallSection/0173d997-####-####-####-########bbb, sending delete section message 2021-03-25T05:47:50.335Z INFO http-nio-127.0.0.1-7440-exec-22 NsxBaseRestController - - [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] Error in API /nsxapi/api/v1/firewall/sections/0173d997-####-####-####-########bbb/state caused by exception com.vmware.nsx.management.firewall.exceptions.FirewallException: {"moduleName":"NSX Firewall","errorCode":100251,"errorMessage":"Firewall is disabled. Can not get realization status."}
From NSX-T 3.1.0, the product has been improved to not report "In Progress" status on the Gateway Firewall when rules are disabled.
Workaround:
Ignore the "in progress" state or do not use "disabled" on firewall.
Impact/Risks:
The status reflects that some sections of firewall are in Disable state. There is no functional impact of the firewall.