After performing a ESXi upgrade, the "netopa" outbound firewall rule may disappear from the [Configure] - [Firewall] settings of specific ESXi hosts in the vSphere Client.
VMware ESXi
VMware Aria Operations for Networks
The ESXi firewall module failed to properly reload or parse the existing /etc/vmware/firewall/netOPARuleset.xml file into the active running configuration following the upgrade or host reboot.
To resolve this issue, manually refresh the ESXi firewall rulesets to reload the configuration from the disk.
esxcli network firewall refreshesxcli network firewall ruleset list | grep netopaThe netopa (Network Operations Agent) service is utilized by Aria Operations for Networks to collect inter-host latency data via TCP port 1991.
For more information on managing the ESXi firewall via CLI, refer to:
Using ESXCLI Firewall Commands to Configure ESXi Behavior