This is a known issue affecting VMware NSX for vSphere 6.4.11.
Issue is resolved in 6.4.12.
Avoid using services with port ranges in the firewall rules configuration before upgrading.
Instead, entering a comma-separated list of all port numbers not exceeding 15 entries in one rule would help.
Example below
sourceport: 8080
value: '1024,1025-1029'
sourceport: 8080
value: '1024,1025,1026,1027,1028,1029'