With 3rd party service appliances, there is the option to 'fail open' in the event of a failure. By default, NSX will drop all traffic if it can't be forwarded to the PAN SVM via the dvfilter slowpath, which is normal in the 'fail closed' configuration. This can happen if the appliance hangs up, crashes or gets powered off for whatever reason. In a 'fail open' scenario, the PAN slowpath is bypassed in the event of a failure. Obviously there can be security considerations here. If L7 filtering is critical, this is probably not an option for you. The DFW (slot-2) filtering will continue to work, but all inspection by the PAN will be bypassed.
Hope this helps.My blog: https://vswitchzero.com
Follow me on Twitter: @vswitchzero