In a Federation environment, disabling the Distributed Firewall (DFW) service from the Global Manager (GM) is expected to propagate the disabled state across all ESXi hosts within all associated Local Manager (LM) sites.
However, in certain scenarios, an inconsistency may be observed wherein ESXi hosts in one or more LM sites continue to report the DFW status as enabled, even though the configuration is shown as disabled in both the Global Manager and Local Manager user interfaces.
Symptoms
Deployment Type : Federation
NSX Version : 4.2.3.3 or earlier version
VMware vDefend Firewall
The issue is caused by a stale or orphaned record in one of the Corfu database tables. This inconsistency is typically introduced during upgrades from earlier NSX versions.
A permanent fix for this issue will be available in NSX 4.2.4 / 9.1.0 or later releases.
Workaround:
The issue can be addressed by deleting the stale records. Please open a case with Broadcom Support vDefend firewall team to implement the workaround.
PR 3610675
./nsx_manager/var/log/proton/nsxapi.1.log.gz:2025-10->29T20:25:00.179Z WARN providerTaskExecutor-1-104 DfwFirewallConfigurationUtils 77545 POLICY [nsx@6876 comp="nsx->manager" level="WARNING" subcomp="manager"] Found no or more than one records in internal table >'InternalDfwFirewallConfiguration', expected exactly one. Proceed to fetch from policy intent