That means you have asymmetric routing somehow/somewhere, not enough there to tell you where. Traffic isn't routing through the firewall in both directions, or it may get routed back in the wrong direction for some reason. Can't statefully filter such traffic with any firewall, most likely you need to fix whatever is causing that to happen (though there are other work arounds, they won't leave you with an extremely tight firewall).
Is there any tool to discover whats wrong?
Cant be esxi?
When you say whatever is causing that, what should I look for?, a broken switch?, a misconfigured virtual switch?,