VMware NSX
This issue occurs when the Check Point appliance performs high-frequency API polling for NSX group memberships (e.g., GET /policy/api/v1/infra/domains/default/groups/<uuid>/members/ip-addresses).
When these requests target a single NSX Manager node or burst above the per-client rate limit (default 100 requests per second), NSX-T throttles the requests. The Check Point Controller interprets these failed API responses as an "empty group" and removes the associated identities from the security policy.
To resolve this issue, the API load must be distributed and the management plane capacity increased: