I'm having trouble interpreting this link for deployment scenarios of the vm series Palo Firewalls. Looking for clarification... https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi.html We have an ESXi cluster with 3 hosts running vSphere Distributed Switches. Our plan is to have one Palo VM-300 in the cluster and it will have the gateways (SVI's) for VM's on all ESXi hosts. I'm questioning if this will work. I'm questioning how a VM on host without the Palo will reach it's gateway. Can this one Palo take traffic from all VM's across all hosts? I feel like I'm missing something here.
... View more