When a guest VM is vMotioned from one host to
another within a cluster, the target host NSX distributed firewall
will steer all new sessions to the VM-Series firewall on the destination
host. To ensure that all active (existing sessions) remain uninterrupted
during and after the guest vMotion, the NSX Manager polls the VM-Series firewall
for existing allowed sessions and then shares these sessions with
the NSX distributed firewall on the destination host. All existing
sessions that were allowed by the original VM-Series will be allowed by
the NSX distributed firewall (filtering module) on the destination
host without steering to the target host VM-Series firewall to prevent
session loss.