API Status
<hostStatus>
<hostId>host-###</hostId>
<hostName>example.local</hostName>
<status>publish_failed</status>
<errorMessage>errorcode.301034</errorMessage>
<errorCode>301034</errorCode>
<startTime>1548839862774</startTime>
<endTime>1549367457383</endTime>
<generationNumber>1548839861809</generationNumber>
<clusterId>domain-c#</clusterId>
<generationNumberObjects>1549350096435</generationNumberObjects>
</hostStatus>
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########0c0f.002
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########0c0f.001
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########0c0f.000
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########6361.000
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########e1bd.000
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########e754.000
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########ad5b.000
2019-02-05T12:02:15Z vsfwd: [WARN] ioctl failed, errno=22
2019-02-05T12:02:15Z vsfwd: [WARN] Failed to apply RuleSet 1549368134646 for vnic ########-####-####-####-########c44
2019-02-05T12:02:15.750Z cpu36:27543657)VSIPFixRuleCtrlPort: unsupported dst port op 10 for dynamic rule!
2019-02-05T12:02:15.750Z cpu36:27543657)pf_rollback_rules: rs_num: 1, anchor: domain-c#
2019-02-05T12:02:15.750Z cpu36:27543657)pf_rollback_rules: rs_num: 2, anchor: domain-c#
2019-02-05T12:02:15.750Z cpu36:27543657)pf_rollback_rules: rs_num: 4, anchor: domain-c#
2019-02-05T12:02:15.756Z cpu36:27543657)VSIPFixRuleCtrlPort: unsupported dst port op 10 for dynamic rule!
2019-02-05T12:02:15.756Z cpu36:27543657)pf_rollback_rules: rs_num: 1, anchor: domain-c#
2019-02-05T12:02:15.756Z cpu36:27543657)pf_rollback_rules: rs_num: 2, anchor: domain-c#
2019-02-05T12:02:15.756Z cpu36:27543657)pf_rollback_rules: rs_num: 4, anchor: domain-c#
2019-02-05T12:02:15.761Z cpu36:27543657)VSIPFixRuleCtrlPort: unsupported dst port op 10 for dynamic rule!
2019-02-05T12:02:15.761Z cpu36:27543657)pf_rollback_rules: rs_num: 1, anchor: domain-c#
2019-02-05T12:02:15.761Z cpu36:27543657)pf_rollback_rules: rs_num: 2, anchor: domain-c#
2019-02-05T12:02:15.761Z cpu36:27543657)pf_rollback_rules: rs_num: 4, anchor: domain-c#
2019-02-05T12:02:15.766Z cpu36:27543657)VSIPFixRuleCtrlPort: unsupported dst port op 10 for dynamic rule!
2019-02-05T12:02:15.766Z cpu36:27543657)pf_rollback_rules: rs_num: 1, anchor: domain-c#
2019-02-05T12:02:15.766Z cpu36:27543657)pf_rollback_rules: rs_num: 2, anchor: domain-c#
2019-02-05T12:02:15.766Z cpu36:27543657)pf_rollback_rules: rs_num: 4, anchor: domain-c#
2019-02-05T12:02:15.772Z cpu36:27543657)VSIPFixRuleCtrlPort: unsupported dst port op 10 for dynamic rule!
This issue occurs because while configuring FW Rules for ALG services such as FTP/ ORACLE/SUNRPC/DCERPC, multiple ports have been specified. It is not supported to specify multiple ports for a single ALG firewall rule.
For example:
rule 1000 at 0 inout protocol tcp from addrset ip-securitygroup-## to addrset ip-securitygroup-## port {1521, 1522, 1525} with attribute addrset attr_###_#_APP_ID accept as oracle;
This issue is resolved in VMware NSX for vSphere 6.4.5.