<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow VMware Workstation created VM's to work on physical PA-820? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-vmware-workstation-created-vm-s-to-work-on-physical/m-p/508031#M105786</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224742"&gt;@R.Tryba&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Sounds like you have a routing issue. I'd verify on your PC that your route table is actually setup how you wish to route traffic, along with verifying that you have the virtual router routes setup properly.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 00:06:35 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-07-06T00:06:35Z</dc:date>
    <item>
      <title>How to allow VMware Workstation created VM's to work on physical PA-820?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-vmware-workstation-created-vm-s-to-work-on-physical/m-p/507996#M105784</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;My home setup includes PC with multiple NIC's and a VMware Workstation that has my virtual lab (Windows domain controller, 5 ESXi&amp;nbsp; 7 hosts, VCSA and some other stuff) This is licenced via VMUG programme.&lt;/P&gt;&lt;P&gt;My main PC goes through one of NIC's direct to PA-820, VMWorkstation is 'bridged' to one of other NIC's I have. Separate subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have created new zone, NAT and security policy to allow all traffic from VMware-assigned PA-820 NIC/zone to 'any' zone - to get any input data. Have applied management profile that allows ping to zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem: I cannot make VCSA to connect to Internet. All traffic I can see is that from IP address that is assigned to 'bridged' NIC on main PC to IP assigned to PA's interface.&lt;/P&gt;&lt;P&gt;Tried amending NAT policy to include PA's address (IP_VMUG_Router) in NAT policy, it does not work with and without that.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20220705-PA_NAT.JPG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42147i76470ADC4FC20F04/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="20220705-PA_NAT.JPG" alt="20220705-PA_NAT.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Security policy looks like that (Speedy is my main PC's zone):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20220705-PA_secpolicy.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42148iBCFF167EFDC9E782/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="20220705-PA_secpolicy.JPG" alt="20220705-PA_secpolicy.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;IP's are:&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.172.71 - DHCP assigned IP to physical NIC 'bridged' to VMWorkstation network segment.&lt;/P&gt;&lt;P&gt;192.168.172.1 - IP of PA-820's interface for that zone&lt;/P&gt;&lt;P&gt;192.168.100.x - main PC's subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping from main PC to all IP's used in VMUG zone.&lt;/P&gt;&lt;P&gt;I can ping from VM's in VMUG zone to PA's NIC IP.&lt;/P&gt;&lt;P&gt;I cannot ping from any VM to anything outside of VMUG zone, neither on Speedy or Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where do I go wrong? I wonder if my main PC understands that one of NIC's has IP from 192.168.172.x subnet and pings direct to NIC? I can see ping traffic on PA from 192.168.172.71 to 192.168.172.1 only..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 19:24:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-vmware-workstation-created-vm-s-to-work-on-physical/m-p/507996#M105784</guid>
      <dc:creator>R.Tryba</dc:creator>
      <dc:date>2022-07-05T19:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow VMware Workstation created VM's to work on physical PA-820?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-vmware-workstation-created-vm-s-to-work-on-physical/m-p/508031#M105786</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224742"&gt;@R.Tryba&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Sounds like you have a routing issue. I'd verify on your PC that your route table is actually setup how you wish to route traffic, along with verifying that you have the virtual router routes setup properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:06:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allow-vmware-workstation-created-vm-s-to-work-on-physical/m-p/508031#M105786</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-07-06T00:06:35Z</dc:date>
    </item>
  </channel>
</rss>

