<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic vm palo question on interfaces for esxi in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/449708#M100968</link>
    <description>&lt;P&gt;We have an exisiting vmware esxi environment that has 3 hosts with distributed switches configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, each esxi host has 4 links (all trunks) going to the physical uplink switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've installed a VM palo series firewall and have established managment connectivity to it via eth1/0 with no issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we are configuring sub interfaces on the vm palo and will point the vm's to it as their gateways.&amp;nbsp; I think this part is working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where our issue is happening is on the uplink from the vm palo to the physical switch.&amp;nbsp; I'm confused how this works as all the uplinks are trunks and I need to have the connection from the physical switch to the palo vm as a L3 link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone break this down for me?&amp;nbsp; Does the questione even make sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More info&lt;/P&gt;&lt;P&gt;I have a SVI on the physical Cisco switch. 10.1.1.1/24&lt;/P&gt;&lt;P&gt;I configured eth1/1 on the vm palo as a L3 link as 10.1.1.2/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have sub interfaces 10.1.80.1/24 (vlan 80) and 10.1.90.1/24 (vlan90) created off of eth1/2 of the VM Palo and they will be gateways for the virtual machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The palo virtual router is set with a default router of 10.1.1.1 to the physical switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly without any routing, I would think that I should be able to ping from the physical switch to the 10.1.1.2 as it should be directly connected but that's not working even with the management profile applied.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So confused!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Nov 2021 14:40:58 GMT</pubDate>
    <dc:creator>geewiss</dc:creator>
    <dc:date>2021-11-30T14:40:58Z</dc:date>
    <item>
      <title>vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/449708#M100968</link>
      <description>&lt;P&gt;We have an exisiting vmware esxi environment that has 3 hosts with distributed switches configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, each esxi host has 4 links (all trunks) going to the physical uplink switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've installed a VM palo series firewall and have established managment connectivity to it via eth1/0 with no issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we are configuring sub interfaces on the vm palo and will point the vm's to it as their gateways.&amp;nbsp; I think this part is working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where our issue is happening is on the uplink from the vm palo to the physical switch.&amp;nbsp; I'm confused how this works as all the uplinks are trunks and I need to have the connection from the physical switch to the palo vm as a L3 link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone break this down for me?&amp;nbsp; Does the questione even make sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More info&lt;/P&gt;&lt;P&gt;I have a SVI on the physical Cisco switch. 10.1.1.1/24&lt;/P&gt;&lt;P&gt;I configured eth1/1 on the vm palo as a L3 link as 10.1.1.2/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have sub interfaces 10.1.80.1/24 (vlan 80) and 10.1.90.1/24 (vlan90) created off of eth1/2 of the VM Palo and they will be gateways for the virtual machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The palo virtual router is set with a default router of 10.1.1.1 to the physical switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly without any routing, I would think that I should be able to ping from the physical switch to the 10.1.1.2 as it should be directly connected but that's not working even with the management profile applied.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So confused!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:40:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/449708#M100968</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-11-30T14:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/449722#M100970</link>
      <description>&lt;P&gt;BTW, I do not have a license installed yet.&amp;nbsp; Could that be the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 22:39:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/449722#M100970</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-11-26T22:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450395#M101044</link>
      <description>&lt;P&gt;Thought I'd try to draw this out.&amp;nbsp; Attached is what I've come up with.&amp;nbsp; Please let me know what you think and how off I am.&amp;nbsp; Any/all feedback welcomed.&amp;nbsp; Thank you!&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palo.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37848i4D0F570F0C6A0BF1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palo.jpg" alt="palo.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450395#M101044</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-11-30T14:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450397#M101045</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201083"&gt;@geewiss&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will ask you to verify below points.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Make sure the proper VLAN mapping (VLAN for subnet &lt;SPAN&gt;10.1.1.0/24&lt;/SPAN&gt;) is done on esxi side for the Palo Alto VM eth1/1 nic. If its not then you need to fix it.&lt;/P&gt;
&lt;P&gt;2. Also you need to make sure VLAN for subnet &lt;SPAN&gt;10.1.1.0/24&lt;/SPAN&gt; is flowed till the esxi. You need to verify your esxi physical connectivity and check if VLAN for subnet&amp;nbsp;&lt;SPAN&gt;10.1.1.0/24&lt;/SPAN&gt; is available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also in the attached diagram, I see you have configured VLAN20 for the palo alto eth1/1 but as per information given, VLAN 20 belongs to&amp;nbsp;&lt;SPAN&gt;10.1.20.1/24. So in this case, subnet&amp;nbsp;10.1.1.0/24 should have different vlan id. You need to verify this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450397#M101045</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-11-30T14:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450400#M101046</link>
      <description>&lt;P&gt;1.&amp;nbsp; Proper vlan maping is done on the esxi side.&amp;nbsp; I think i'm good there.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Vlan is flowed till the esxi.&amp;nbsp; Should be good there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I fixed the original post.&amp;nbsp; Vlan 20 is only on the physical switch to the external vds.&amp;nbsp; Vlan 80,90 are on the interal vds with different id's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess my real question is .....will the physical links work like this were I have access port and trunk ports terminated to the physical from the external vds?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help and clarification!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 14:44:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450400#M101046</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-11-30T14:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450472#M101053</link>
      <description>&lt;P&gt;I'm wondering if anyone has ever done a setup like this?&amp;nbsp; Does it even make sense?&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 20:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450472#M101053</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-11-30T20:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450558#M101065</link>
      <description>&lt;P&gt;License shouldn’t be the issue here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 04:34:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450558#M101065</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-12-01T04:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450638#M101070</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201083"&gt;@geewiss&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If any of the palo alto interface is configured as a L3 sub-interface, then you need to configure neighboring device interface as a trunk then you can flow specific vlan traffic via that trunk port. If Palo Alto interface is configured as normal L3 interface then keeping&amp;nbsp;neighboring device interface in access port should work.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 14:21:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/450638#M101070</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-12-01T14:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: vm palo question on interfaces for esxi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/451082#M101114</link>
      <description>&lt;P&gt;UPDATE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The key here was to make all 4 physical links from the ESXi host to the physical switch as trunks.&amp;nbsp; Then to have the e1/1 interface on the palo configured in a port group that is "vlan trunking".&amp;nbsp; Then to have a sub interface on the palo with tagging the vlan number.&amp;nbsp; This seem to work.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 21:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-palo-question-on-interfaces-for-esxi/m-p/451082#M101114</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-02T21:40:13Z</dc:date>
    </item>
  </channel>
</rss>

