<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMs cannot ping gateway / subinterface on Palo firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330133#M83722</link>
    <description>&lt;P&gt;Why do not you allocate a dedicated interface to the VLAN14 on Palo? Even if that trunking can work in principle there is still so many places where dot1q can go wrong in a virtualized environment...&amp;nbsp; &amp;nbsp;You need to make sure that VGT is configured correctly (&lt;A href="https://kb.vmware.com/s/article/1003806#vgtPoints" target="_blank"&gt;https://kb.vmware.com/s/article/1003806#vgtPoints&lt;/A&gt;&amp;nbsp;), you need to make sure Palo uses hypervisor-assigned MAC address (Device &amp;gt; Management &amp;gt; General Settings).&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2020 17:04:05 GMT</pubDate>
    <dc:creator>Nikolay-Matveev</dc:creator>
    <dc:date>2020-05-27T17:04:05Z</dc:date>
    <item>
      <title>VMs cannot ping gateway / subinterface on Palo firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330121#M83721</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am kind a new with PaloAlto. I require some help with a scenario I try to put into practice in my lab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a strange situation in my setup.&lt;/P&gt;&lt;P&gt;I have deployed a PaloAlto firewall virtual appliance on a ESXi host. And also created 2 Virtual machines.&lt;BR /&gt;On PaloAlto, I have created a subinterface and assigned it to vlan 14 and an interface, assigned to Vlan 12. Vlan 12 communicates with the exterior.&amp;nbsp;&lt;BR /&gt;The to VMs are assigned to Vlan 14.&lt;/P&gt;&lt;P&gt;No here is the strange thing. The vms can ping to each other, but they cannot ping the gateway, which is the subinterface I have created on PaloAlto, Vlan 14.&lt;BR /&gt;However, the subinterface can be ping-ed if I try from outside the VmWare environment, via Vlan 12, from my phisical computer for example.&lt;/P&gt;&lt;P&gt;The physical computer runs in a different network, and communicates with the vmware environment via a firewall, physical box. The firewall (physical box) communicates with PaloAlto using Vlan 12.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached the config of the PaloAlto interface/subinterface fw and config for the virtual Nics in vmware.&lt;BR /&gt;Both port groups in VmWare use the same physical interface, in VmWare.&lt;BR /&gt;The interfaces in PaloAlto is configured to respond to PING.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What exactly am I missing in order to allow the VMs to ping the gateway and allow them access towards other networks?&lt;/P&gt;&lt;P&gt;Any tips much appreciated!&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo cfg.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25864i2A1D75866BF3F99F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Palo cfg.PNG" alt="Palo cfg.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vlan 14.PNG" style="width: 344px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25865iC54E0CFE102B25CB/image-dimensions/344x218/is-moderation-mode/true?v=v2" width="344" height="218" role="button" title="vlan 14.PNG" alt="vlan 14.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Trunk.PNG" style="width: 341px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25866i303169DB12F498D5/image-dimensions/341x208/is-moderation-mode/true?v=v2" width="341" height="208" role="button" title="Trunk.PNG" alt="Trunk.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 16:12:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330121#M83721</guid>
      <dc:creator>alexwi</dc:creator>
      <dc:date>2020-05-27T16:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: VMs cannot ping gateway / subinterface on Palo firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330133#M83722</link>
      <description>&lt;P&gt;Why do not you allocate a dedicated interface to the VLAN14 on Palo? Even if that trunking can work in principle there is still so many places where dot1q can go wrong in a virtualized environment...&amp;nbsp; &amp;nbsp;You need to make sure that VGT is configured correctly (&lt;A href="https://kb.vmware.com/s/article/1003806#vgtPoints" target="_blank"&gt;https://kb.vmware.com/s/article/1003806#vgtPoints&lt;/A&gt;&amp;nbsp;), you need to make sure Palo uses hypervisor-assigned MAC address (Device &amp;gt; Management &amp;gt; General Settings).&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 17:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330133#M83722</guid>
      <dc:creator>Nikolay-Matveev</dc:creator>
      <dc:date>2020-05-27T17:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: VMs cannot ping gateway / subinterface on Palo firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330145#M83726</link>
      <description>&lt;P&gt;Hello Nikolay,&lt;/P&gt;&lt;P&gt;Doing as you have suggested, works fine. Thank you!&lt;/P&gt;&lt;P&gt;I am very curious in trying the other alternative as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not properly configure the VGT. So this must be the issue.&lt;/P&gt;&lt;P&gt;Thank you again for your quick respons.&lt;/P&gt;&lt;P&gt;Best regards!&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 18:04:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vms-cannot-ping-gateway-subinterface-on-palo-firewall/m-p/330145#M83726</guid>
      <dc:creator>alexwi</dc:creator>
      <dc:date>2020-05-27T18:04:14Z</dc:date>
    </item>
  </channel>
</rss>

