<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Physical connections to vSphere cluster for VM-200 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/physical-connections-to-vsphere-cluster-for-vm-200/m-p/76398#M42299</link>
    <description>&lt;P&gt;Hey folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone point me to a "best practice" design guide or white paper for making the physical connections to a vSphere cluster that will run a VM-200 virtual appliance? I'm only seeing configuration guides on deploying and setting up the VM on a vSphere host but nothing on how best to &amp;nbsp;make the physical connections to the hosts-especially a VM farm cluster. We have a 50Mb Internet connection at a remote location that we are replacing a low end SOHO type firewall with a VM-200. We are setting it up in a 2 node vSphere cluster that will only house externally facing VMs (VMs also are available for internal users so). So one vmnic will connect to the ISP's connection, another will be the DMZ and the third will be the LAN side. &amp;nbsp;The question is how best to physically connect everything so in the event one of the ESXi hosts goes down, vSphere HA can power the VM-200 up on the other host and all the connections be there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My initial "design" is use three physical switches and to bring the ISP's connection to a switch and make two vSphere vmnic connections to that switch, place security on the ports so that only those ports can communicate with each other. Then make a second vmnic connection from both hosts to a DMZ switch which will have DMZ VMs on it (web servers and so on) and then finally a third switch which will be on the LAN side. Is this a good way to do it? Overkill?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or I suppose by using VLANs and port ACLs, I could use a single switch but is that a "best practice"?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IIUC, traffic inbound would then flow from ISP &amp;gt;&amp;gt; WAN switch &amp;gt;&amp;gt; host1 or host2 &amp;gt;&amp;gt; PA-200 &amp;gt;&amp;gt; DMZ switch &amp;gt;&amp;gt; DMZ target and then for internal access to DMZ resources it will flow from LAN &amp;gt;&amp;gt; host1 or host2 &amp;gt;&amp;gt; PA-200 &amp;gt;&amp;gt; DMZ switch &amp;gt;&amp;gt; DMZ target. In all cases, traffic does not get to DMZ without going through the PA-200 and traffic leaving the DMZ returning to WAN or LAN also goes through the PA-200.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA-200 will have the following vNICs:&lt;/P&gt;
&lt;P&gt;vNIC1 = WAN&lt;/P&gt;
&lt;P&gt;vNIC2 = DMZ&lt;/P&gt;
&lt;P&gt;vNIC3 = LAN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vNIC4 = Management&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each vSphere host will have the following physical NICs:&lt;/P&gt;
&lt;P&gt;vmnic0 = Host management&amp;nbsp;network&lt;/P&gt;
&lt;P&gt;vmnic1 = WAN&lt;/P&gt;
&lt;P&gt;vmnic2 = DMZ&lt;/P&gt;
&lt;P&gt;vmnic3 = Internal &amp;nbsp;LAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each vSphere host will have the following vSwitches:&lt;/P&gt;
&lt;P&gt;vSwitch0 = Management&lt;/P&gt;
&lt;P&gt;vSwitch1&amp;nbsp;= WAN&lt;/P&gt;
&lt;P&gt;vSwitch2 = DMZ&lt;/P&gt;
&lt;P&gt;vSwitch3 = LAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new to Palo Alto and may not be understanding a lot so any pointers to documentation or diagrams on connectivity as described above would be helpful. I also realize that this is heavy on the vSphere side but I'd hate to make a bone headed mistake and expose our network to risk by not asking the question. I also hope I have complicated a simple deal!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2016 04:21:22 GMT</pubDate>
    <dc:creator>markdean</dc:creator>
    <dc:date>2016-04-14T04:21:22Z</dc:date>
    <item>
      <title>Physical connections to vSphere cluster for VM-200</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/physical-connections-to-vsphere-cluster-for-vm-200/m-p/76398#M42299</link>
      <description>&lt;P&gt;Hey folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone point me to a "best practice" design guide or white paper for making the physical connections to a vSphere cluster that will run a VM-200 virtual appliance? I'm only seeing configuration guides on deploying and setting up the VM on a vSphere host but nothing on how best to &amp;nbsp;make the physical connections to the hosts-especially a VM farm cluster. We have a 50Mb Internet connection at a remote location that we are replacing a low end SOHO type firewall with a VM-200. We are setting it up in a 2 node vSphere cluster that will only house externally facing VMs (VMs also are available for internal users so). So one vmnic will connect to the ISP's connection, another will be the DMZ and the third will be the LAN side. &amp;nbsp;The question is how best to physically connect everything so in the event one of the ESXi hosts goes down, vSphere HA can power the VM-200 up on the other host and all the connections be there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My initial "design" is use three physical switches and to bring the ISP's connection to a switch and make two vSphere vmnic connections to that switch, place security on the ports so that only those ports can communicate with each other. Then make a second vmnic connection from both hosts to a DMZ switch which will have DMZ VMs on it (web servers and so on) and then finally a third switch which will be on the LAN side. Is this a good way to do it? Overkill?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or I suppose by using VLANs and port ACLs, I could use a single switch but is that a "best practice"?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IIUC, traffic inbound would then flow from ISP &amp;gt;&amp;gt; WAN switch &amp;gt;&amp;gt; host1 or host2 &amp;gt;&amp;gt; PA-200 &amp;gt;&amp;gt; DMZ switch &amp;gt;&amp;gt; DMZ target and then for internal access to DMZ resources it will flow from LAN &amp;gt;&amp;gt; host1 or host2 &amp;gt;&amp;gt; PA-200 &amp;gt;&amp;gt; DMZ switch &amp;gt;&amp;gt; DMZ target. In all cases, traffic does not get to DMZ without going through the PA-200 and traffic leaving the DMZ returning to WAN or LAN also goes through the PA-200.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA-200 will have the following vNICs:&lt;/P&gt;
&lt;P&gt;vNIC1 = WAN&lt;/P&gt;
&lt;P&gt;vNIC2 = DMZ&lt;/P&gt;
&lt;P&gt;vNIC3 = LAN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vNIC4 = Management&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each vSphere host will have the following physical NICs:&lt;/P&gt;
&lt;P&gt;vmnic0 = Host management&amp;nbsp;network&lt;/P&gt;
&lt;P&gt;vmnic1 = WAN&lt;/P&gt;
&lt;P&gt;vmnic2 = DMZ&lt;/P&gt;
&lt;P&gt;vmnic3 = Internal &amp;nbsp;LAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each vSphere host will have the following vSwitches:&lt;/P&gt;
&lt;P&gt;vSwitch0 = Management&lt;/P&gt;
&lt;P&gt;vSwitch1&amp;nbsp;= WAN&lt;/P&gt;
&lt;P&gt;vSwitch2 = DMZ&lt;/P&gt;
&lt;P&gt;vSwitch3 = LAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new to Palo Alto and may not be understanding a lot so any pointers to documentation or diagrams on connectivity as described above would be helpful. I also realize that this is heavy on the vSphere side but I'd hate to make a bone headed mistake and expose our network to risk by not asking the question. I also hope I have complicated a simple deal!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 04:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/physical-connections-to-vsphere-cluster-for-vm-200/m-p/76398#M42299</guid>
      <dc:creator>markdean</dc:creator>
      <dc:date>2016-04-14T04:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Physical connections to vSphere cluster for VM-200</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/physical-connections-to-vsphere-cluster-for-vm-200/m-p/449721#M100969</link>
      <description>&lt;P&gt;I'm curious, did you ever get this sorted out.&amp;nbsp; I have a similar requirement and can't seem to get it working.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 21:52:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/physical-connections-to-vsphere-cluster-for-vm-200/m-p/449721#M100969</guid>
      <dc:creator>geewiss</dc:creator>
      <dc:date>2021-11-26T21:52:13Z</dc:date>
    </item>
  </channel>
</rss>

