NCM stops the firewalld / iptables service so that the required ports used by NCM are not Interrupted during installation, causing communication issues/installation failures.
Refer NCM Security Configuration guide for the ports needed to be open for NCM operations. If the required ports are permitted, firewalld/iptables can be started manually after NCM installation.
https://docs.vmware.com/en/VMware-Smart-Assurance/10.1.4/ncm-security-configuration-guide-1014.pdf