Since this is nested;
Make sure that the VM of the nested ESXi's portgroups are the portgroup with all the security functions turned on and is a trunking port group, this should be the portgroup created on your single physical esxi host. Then in the ESXi VM, ensure the management interface is tagged with the management VLAN. Also ensure all VLANs are trunked to your ESXi host from the physical network fabric.
It sounds like there is bad config somewhere.