NSX Edges firewall is not called into action for protecting instances or configured through OpenStack Security Groups (VIO uses NSX DFW and NSX Security Groups for that): it is configured behind the scenes to allow DHCP traffic for instances and connectivity between tenant virtual networks.