When firewall rules are sent to multiple sleds, only a single error is currently handled (as of PR #1636). We should have some form of long-running, retry-style error handling in case something goes wrong on more than one sled.
Originally raised by @bnaecker in #1636 (comment)