The number of T0/T1 Service routers ... has exceeded the maximum threshold of 98%"Though the Gateway Firewall state is still shown as "ON" in NSX-T, the rules that are added/removed from it decides whether firewall is applied on traffic/not
The behaviour observed is an expected behaviour. When we disable Firewall from VCD we don't expect any rules to be applied, while the firewall is enabled rules take effect irrespective of the TOGGLE state in NSX-T.
Engineering is aware of this and will address this in a future release of VMware Cloud Director.
For more information regarding the error in NSX-T. See Service Router Limit Per Edge Exceeded - Critical Alert: "The number of T0/T1 Service routers ... has exceeded the maximum threshold of 98%"