Although a recurrent request, the use of Open VM Tools on guest or workload virtual machines has never been validated with NSX Distributed Firewall. It got quite unnoticed, but a small sentence in the NSX for vSphere 6.3.2 Release Notes changed the game:
**Starting in NSX 6.3.2, Open VM Tools is supported with Distributed Firewall.** In NSX, VMware Tools are required to translate vCenter objects into IP. Indeed, the underlying NSX distributed firewall rules configured within the kernel are IP-based, despite being abstracted as objects at the configuration layer so it is a requirement to run VMware tools in all virtual machines so their addresses are reported into vCenter. ...