Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Settings for getting Hyper-V working in PAN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Settings for getting Hyper-V working in PAN

Not applicable

setupHello,

I have been struggling with this all day, and I think I have it narrowed down, but can't seem to nail it down yet.

I have a test Hyper-V 2012 server in the data center, and all my services are working properly, except being able to connect to the VM's via Virtual Machine Connection. It uses TCP Port 2179 and is basically RDP, just running on this port instead of 3389. I have everything else working properly, but for some reason, when I either add a service with this port, it breaks MSRPC application, and if I add the tcp port to an application object, it still doesn't work. Looking at the logs and the pcaps, the firewall is doing what it is supposed to and dropping them, but it shouldn't be if I have the rules setup.

After spending 8 hours searching Google, Bing, Yahoo, Ask, and countless other search engines, including here, I have found not a single person or organization that is running Hyper-V behind a Palo Alto Firewall.

Any direction as to how to setup the Application or the Service to get this working would be great. Currently I have this server doing an allow all from both zones, so basically this server is not being protected by my firewall at all.

Any help would be greatly appreciated.

Thanks,

Lucas Williams

1 accepted solution

Accepted Solutions

Not applicable

I figured it out. I ended up moving away from the App-ID way and going with services. I just looked at the network flow and seen what ports were being called and created services for each port and then put them into a Service Group and applied it to my Hyper-V rule and now everything is working.

View solution in original post

3 REPLIES 3

Not applicable

I figured it out. I ended up moving away from the App-ID way and going with services. I just looked at the network flow and seen what ports were being called and created services for each port and then put them into a Service Group and applied it to my Hyper-V rule and now everything is working.

Thanks for following up on this one, I'm sure it will help other folks who are in a Hyper-V environment

Do be more specific what I did:

  1. I created the following Services with these ports
    1. ms-rpc: tcp/135,49154
    2. ms-ds-smb-tcp: tcp/445,139
    3. ms-ds-smb-udp: udp/445
    4. hyper-v-rdp: tcp/2179
  2. I then created a Service Group called Hyper-V-SVG and added those services to it.
  3. I applied this service group to my Hyper-V server rule Allowing it and everything worked!
  • 1 accepted solution
  • 4068 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!