VM300 Live Migration - MS HyperV S2D - MAC Address/ MAC Spoofing

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VM300 Live Migration - MS HyperV S2D - MAC Address/ MAC Spoofing

L0 Member

We have a 4 node Hyper V S2D cluster with a single VM300 appliance.  We have been able to successfully live migrate the VM from node to node without any issues.

We are in the process of modifying the North / South network fabric.  I have successfully update the network on 3 of the 4 nodes.  When I went to do the final node (the node that the VM300 resides on), I live migrated the VM to one of the other nodes.  When I did the migration all network connectivity in and out of the PAN VM300 stopped.

Through troubleshooting it looked as though there was a possible issue with the way the MAC addresses of the appliance were setup.

Has anyone successfully setup a single VM300 in a HyperV cluster and was able to migrate from node to node?  What are the suggested MAC address settings in the appliance as well as the S2D cluster vNIC settings for the VM.

 

Old Fabric:

-onboard intel nic (physical) connected to a single Cisco Nexus 9000 switch.  Using HyperV switch for VM traffic managment.

 

New Fabric

-Mellanox ConnectX 4LX NICs, connected to new Cisco Nexus 9000 switches.  Using a HyperV switch configured as a SET (Switch embedded teaming).

1 REPLY 1

L6 Presenter

Have you checked ?

 

https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series-firewall-o...

 

 

 

Also have you anabled promiscuous mode or copied the mac address that the Hyper-V gave to the VM?

 

https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/about-the-vm-series-firewall/hy...

 

 

 

Also have you tested with traditional NIC teaming and not SET as if the issue is with the SET teaming raise a case to Palo Alto TAC?

 

  • 1611 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!