sounds like something in the firewall rules section.
This is the typical formatting of that area, and I think order is important:
<vcloud:FirewallRule>
<vcloud:IsEnabled>true</vcloud:IsEnabled>
<vcloud:Description>Allow all outbound traffic</vcloud:Description>
<vcloud:Policy>allow</vcloud:Policy>
<vcloud:Protocols>
<vcloud:Any>true</vcloud:Any>
</vcloud:Protocols>
<vcloud:Port>-1</vcloud:Port>
<vcloud:DestinationIp>Any</vcloud:DestinationIp>
<vcloud:SourcePort>-1</vcloud:SourcePort>
<vcloud:SourceIp>Any</vcloud:SourceIp>
<vcloud:Direction>out</vcloud:Direction>
<vcloud:EnableLogging>false</vcloud:EnableLogging>
</vcloud:FirewallRule>