This issue occurs if the hostd is not aware of the dynamic rule when auto-deploy attempts to check host compliance after applying the host profile. As a result, the compliance check fails if the host profile contains the dynamic rule set
Actulally this issue occurred 5.5 but I saw it is also exist in 6.0 and solution is same.
- esxcli network firewall set --enabled false
- esxcli network firewall set --enabled true
Again detach reference host and attach then check compliance