<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ESXi deployment question for Palo -VM series (L3 Mode) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452003#M101206</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201083"&gt;@geewiss&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can a VM on one ESXi host reach the other VMs running on a different host within your existing network? The answer to that question would really depend on your environment, but the vast majority of environments the answer would be yes. The deployment method that you use really depends on your own network design and actual goals.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Dec 2021 01:10:07 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-12-08T01:10:07Z</dc:date>
    <item>
      <title>ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/451973#M101205</link>
      <description>&lt;P&gt;I'm having trouble interpreting this link for deployment scenarios of the vm series Palo Firewalls.&amp;nbsp; Looking for clarification...&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi.html" target="_blank"&gt;https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an ESXi cluster with 3 hosts running vSphere Distributed Switches.&amp;nbsp; Our plan is to have one Palo VM-300 in the cluster and it will have the gateways (SVI's) for VM's on all ESXi hosts.&amp;nbsp; I'm questioning if this will work.&amp;nbsp; I'm questioning how a VM on host without the Palo will reach it's gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can this one Palo take traffic from all VM's across all hosts?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel like I'm missing something here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 23:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/451973#M101205</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-07T23:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452003#M101206</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201083"&gt;@geewiss&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can a VM on one ESXi host reach the other VMs running on a different host within your existing network? The answer to that question would really depend on your environment, but the vast majority of environments the answer would be yes. The deployment method that you use really depends on your own network design and actual goals.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 01:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452003#M101206</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-12-08T01:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452004#M101207</link>
      <description>&lt;P&gt;Right now I don't have a way to test it as the gateways for all the VM's will be on the Palo VM.&amp;nbsp; I'm pretty sure all VM's on the physical ESX host with the Palo VM will be fine.&amp;nbsp; What I'm worried about are the VM's that are on other ESX hosts that do not have the Palo.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that make sense?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 01:14:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452004#M101207</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-08T01:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452466#M101246</link>
      <description>&lt;P&gt;I'd like to give some additional details on this as I'm still looking for feedback and am a little confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See attached picture.&amp;nbsp; It represents one physical ESXi host of a cluster of 3.&amp;nbsp; I'm curious if this setup would work and allow network connectivity between VM's on vlans 68 and 69 across all hosts.&amp;nbsp; Please let me know if more detail is needed to answer this question.&amp;nbsp; Thank you!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PXL_20211209_223247127.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38085i3D5AB3EC0A8DC06A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PXL_20211209_223247127.jpg" alt="PXL_20211209_223247127.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 22:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452466#M101246</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-09T22:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452486#M101253</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;From what I remember trying to architect something like this, you would need a PAN on each ESXi host. If you just have one it will/might create major routing issues if the ESXi host the PAN is running on get rebooted etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just another thought. What if instead of your physical switch you had a physical PAN's, 2x in HA,? This way it would all be layer 2 vlans to the PAN and they are all anchored there? Just thinking out loud.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 23:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452486#M101253</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-09T23:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452490#M101255</link>
      <description>&lt;P&gt;I agree with your statement about using two physical Palos but that's not an option for us currently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anyway to do this with one PAN?&amp;nbsp; If not, can you point me to any documentation on the setup for a PAN-VM on each ESXi host?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 23:40:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452490#M101255</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-09T23:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452585#M101270</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check out this article.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi" target="_blank"&gt;https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 20:01:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452585#M101270</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-10T20:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452614#M101278</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also thinking outside the box, how about using Global Protect? This way all the VM's will VPN into the PAN and you now basically have zero trust if you configure the security policies correctly.&lt;/P&gt;
&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 21:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452614#M101278</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-10T21:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452618#M101280</link>
      <description>&lt;P&gt;Thanks for all the replies, I ended up getting my original setup working across all ESXi hosts.&amp;nbsp; Even performed some vmotions of the VM's and even the Palo.&amp;nbsp; VM's were fine to vmotion....with the Palo, things were down for about 30 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I'm having issues with the zones.&amp;nbsp; I can't create any more than 15 even though I have the VM-300 license installed.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 21:56:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452618#M101280</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-10T21:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452622#M101283</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Not sure what the limit on Zones is, however what I did was create one zone and used subnets in it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Zone DNZ-A then use vlan subnets and not allow the subnets to communicate unless they have a reason to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 22:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452622#M101283</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-10T22:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: ESXi deployment question for Palo -VM series (L3 Mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452743#M101295</link>
      <description>&lt;P&gt;According to this link&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloguard.com/VM-Series.asp" target="_blank"&gt;https://www.paloguard.com/VM-Series.asp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should be able to do 40 zones on the VM-300 but for some reason it only allows 15 as it errors when I get to 16.&amp;nbsp; I'm sure the license is installed as I have a serial number and it shows a VM-300 license.&amp;nbsp; I've tried rebooting but still no joy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 00:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esxi-deployment-question-for-palo-vm-series-l3-mode/m-p/452743#M101295</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-12-13T00:59:21Z</dc:date>
    </item>
  </channel>
</rss>

