When checking Host Profile compliance for an ESXi host in a vSphere environment integrated with NSX, the host reports a status of "Not Compliant".
The compliance failure lists the following specific error:
"Ruleset dfwipfix0 not found"
VMware vSphere ESXi 6.x / 7.x / 8.x
VMware NSX / NSX-T
VMware vCenter Server 6.x / 7.x / 8.x
This behavior is expected and by design. The dfwipfix0 firewall ruleset is created dynamically on an ESXi host only when at least one active Virtual Machine connected to an NSX segment is running on that host. If an ESXi host has no running virtual machines or its virtual machines are not attached to NSX-managed segments, the dfwipfix0 ruleset is uninstantiated in the ESXi firewall configuration.
If a Host Profile is extracted from a reference host that has an active dfwipfix0 ruleset, any target host without active NSX-segment virtual machines triggers a non-compliance alert due to the missing rule.
Because the dfwipfix0 firewall ruleset is dynamic and depends entirely on active VM workloads, it should not be used as a static factor for Host Profile compliance.
To resolve the non-compliance status, remove the firewall configuration requirement for this dynamic rule from the Host Profile:
Log in to the vSphere Client.
Navigate to Policies and Profiles > Host Profiles.
Select the affected Host Profile and click Edit Host Profile.
Expand the configuration tree to locate the Security/Firewall settings:
Security and Services > Firewall configuration > Ruleset.
Locate the dfwipfix (or dfwipfix0) ruleset policy.
Uncheck or disable the compliance checking factor for this specific ruleset so it is excluded from validation.
Save the changes to the Host Profile and remediate/re-check compliance on your cluster.
dfwipfix ruleset behavior, refer to KB 389634 nsx-dfw-ipfix-not-displaying-in-esxi