<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VM Series on ESXi not receving OSPF hello packets when connected to EVE-NG in VM-Series in the Private Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544184#M132</link>
    <description>&lt;P&gt;Hello Pavel,&lt;/P&gt;
&lt;P&gt;I appreciate the suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've reviewed the document regarding troubleshooting OSPF adjacencies. It is in fact very helpful. I'm lead to believe that the PA-VM is not receiving the OSPF hello packets and thus not including the other router's Router-ID in the hello packets. I've done Wireshark captures that show that the PA-VM does not initiate a unicast to the Cisco router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The intrazone-default security policy action is set to allow. The behavior I'm seeing on the PA-VM is that traffic can exit but return traffic is not able to get through.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you aware of anything else that's worth checking out?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 May 2023 14:21:24 GMT</pubDate>
    <dc:creator>Spiterman</dc:creator>
    <dc:date>2023-05-31T14:21:24Z</dc:date>
    <item>
      <title>VM Series on ESXi not receving OSPF hello packets when connected to EVE-NG</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/543590#M122</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have set up a PA-VM version 10.2.5 on VMware ESXi as I was not able to get it to work properly on EVE-NG. On ESXi I did the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Added new Port Group to the Virtual Switch&lt;/LI&gt;
&lt;LI&gt;Added a Network Adapter to PA-VM and associated it to the new Port Group
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;This is to configure an interface as Outside on the FW to connect it to my EVE-NG environment&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Added a 2nd Network Adapter to EVE-NG and associated it to the new Port Group
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;This is to add a Network (Cloud1) on EVE-NG to link it the PA-VM&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a Cisco vIOS router running Version 15.8(3)M2 that connects to (Cloud1) and in turn connects to other VMs on the same Port Group including a Cisco C9800-CL-K9_IOSXE. Version 16.12.4a, which can also run OSPF, running directly on my ESXi host, which I also added into the same Port Group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am able to form a full OSPF adjacency with the C9800, but am not able to do so with the PA-VM. The configuration on the PA-VM appears to be correct as I followed the steps to configure OSPF on the PA-VM and I am seeing the Hello messages arrive on the Cisco router running on EVE-NG as well as the C9800 running on ESXi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From Cisco router on EVE-NG:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spiterman_0-1685150873031.png" style="width: 841px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50381i3FD7C3C3EA47028E/image-dimensions/841x103/is-moderation-mode/true?v=v2" width="841" height="103" role="button" title="Spiterman_0-1685150873031.png" alt="Spiterman_0-1685150873031.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spiterman_1-1685150979713.png" style="width: 848px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50382i1551F4483A4B5AA0/image-dimensions/848x270/is-moderation-mode/true?v=v2" width="848" height="270" role="button" title="Spiterman_1-1685150979713.png" alt="Spiterman_1-1685150979713.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From C9800 on ESXi:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spiterman_3-1685151199984.png" style="width: 848px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50384i6A64974832ABF336/image-dimensions/848x89/is-moderation-mode/true?v=v2" width="848" height="89" role="button" title="Spiterman_3-1685151199984.png" alt="Spiterman_3-1685151199984.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spiterman_2-1685151179653.png" style="width: 855px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50383i52A98CEB1EDC2B81/image-dimensions/855x139/is-moderation-mode/true?v=v2" width="855" height="139" role="button" title="Spiterman_2-1685151179653.png" alt="Spiterman_2-1685151179653.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EVE-NG topology:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spiterman_4-1685151332748.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50385i8AF6270A64BADF5C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Spiterman_4-1685151332748.png" alt="Spiterman_4-1685151332748.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see. This is a rather simple setup. It appears that the PA-VM is not receiving the Hello packets from the other devices and thus not responding with updated Hello packets to the other devices to include their own Router-IDs. Hence why the it remains in the INIT state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically, the PA-VMs Hello messages get out, but it is not able to receive them so that it updates it own Hello messages to the other devices and thus proceed to the 2-WAY state and so on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone seen this before? If so, can you help me out or provide some feedback as to what I can try?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've included the PA-VM configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all in advance!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2023 01:50:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/543590#M122</guid>
      <dc:creator>Spiterman</dc:creator>
      <dc:date>2023-05-27T01:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series on ESXi not receving OSPF hello packets when connected to EVE-NG</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544162#M131</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/294457"&gt;@Spiterman&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you please go through this&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLZjCAO" target="_self"&gt;KB&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;
&lt;P&gt;Could you also check whether intrazone-default security policy has action set to allow?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 13:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544162#M131</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-05-31T13:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series on ESXi not receving OSPF hello packets when connected to EVE-NG</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544184#M132</link>
      <description>&lt;P&gt;Hello Pavel,&lt;/P&gt;
&lt;P&gt;I appreciate the suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've reviewed the document regarding troubleshooting OSPF adjacencies. It is in fact very helpful. I'm lead to believe that the PA-VM is not receiving the OSPF hello packets and thus not including the other router's Router-ID in the hello packets. I've done Wireshark captures that show that the PA-VM does not initiate a unicast to the Cisco router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The intrazone-default security policy action is set to allow. The behavior I'm seeing on the PA-VM is that traffic can exit but return traffic is not able to get through.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you aware of anything else that's worth checking out?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 14:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544184#M132</guid>
      <dc:creator>Spiterman</dc:creator>
      <dc:date>2023-05-31T14:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series on ESXi not receving OSPF hello packets when connected to EVE-NG</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544250#M133</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/294457"&gt;@Spiterman&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To me it looks like that initial OSPF neighbor discovery to 224.0.0.5 does not get to PA-VM. Would it be possible to look into logs:&amp;nbsp;&lt;STRONG&gt;tail follow yes mp-log routed.log&lt;/STRONG&gt; to see whether it can provide more insight. Also, would it be possible for a test to change OSPF network type to p2mp (point to multipoint)? With this interface type you have to configure all neighbors manually and initial discovery will be sent by unicast instead of multicast. You will have to match the interface type on Cisco side (I think the interface type will be: ip ospf network point-to-multipoint non-broadcast).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 22:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/vm-series-on-esxi-not-receving-ospf-hello-packets-when-connected/m-p/544250#M133</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-05-31T22:20:21Z</dc:date>
    </item>
  </channel>
</rss>

