get firewall ruleset rules" commandNSX 4.2.x
When a NAT Rule is deleted by Policy Provider from Corfu during the Upgrade because of data migration, an issue with CCP's UFO full sync may occur, and CCP may not propagate this NAT Rule deletion to EdgeNode data plane.
This is a known issue and will be fixed in future NSX version releases.
Workaround
Perform Controller/CCP service restart on all 3 Manager nodes:
/etc/init.d/nsx-ccp restart