And just because you have the distributed switch working on all your hosts, that doesn't have an effect on traffic flow.
In other words, if your virtual firewall is a VM and you build it on one host, connecting that VM to a port group on your distributed switch doesn't also "distribute" copies of the virtual firewall VM to all your other hosts.
-------------------------------------------------------------------------------------------------------------------------------------------------------------
Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog