During a vMotion event, VMtools may temporarily withdraw the IP-to-port binding, even though the IP remains configured on the VM's network interface. During this brief time appropriate DFW rules may not be enforced to the VM.
VMware NSX: 3.x. and 4.x (This issue only impacts the VM's on DVPG)
This issue is caused by the behavior of VMtools-based IP discovery during vMotion events. When a VM is migrated, VMware Tools temporarily withdraws the IP-to-port binding and re-reports it after the migration completes.
Use NSX VLAN-backed or Overlay segments that have vMotion awareness which delays the removal of IP address.