If the NSX Manager-Vsfwd connection is los, NSX dFW continues to function with latest rule tabl. NSX manager updates the dFW to the latest version when the connection occurs again. In failsafe mode, is it required to use default deny any or permit any when there is a problem with the dFW?
Similar feature is that dFW operates in fail-closed mode (does not allow connections) if the ESXi host CPU utilization reaches %100 since it can't check the packet against the rule table.