Palo Alto Networks Knowledgebase: How to Configure Interfaces for VM-Series to Work in L3 without Promiscuous Mode

How to Configure Interfaces for VM-Series to Work in L3 without Promiscuous Mode

13008
Created On 02/07/19 23:37 PM - Last Updated 02/07/19 23:38 PM
Virtual Systems Virtualization
Resolution

Overview

Prior to 7.0, VM-Series firewalls were not able to configure thier logical interfaces to use hypervisor-assigned MAC addresses. So, these firewalls required you either A) to enbable promiscuous mode on the vSwitch port group or B) manually configure the hypervisor to use the MAC address(es) of the firewall. VM-Series firewalls running 7.0 and later do not have this limitation and can now detect and use the MAC address assigned by the hypervisor. In 7.0 and later, using the hyperadvisor-assigned MAC address is the default behavior, but this can be disabled in the Device > Setup > Management  > General Settings configuration.

 

Steps

The following steps describe how to modify the VM network configuration to use the native MAC address of the firewall. For firewalls running PAN-OS versions prior to 7.0, this will enable you to connect the firewall to your virtual infrastructure without requiring you to enable promiscuous mode on vSwitch port group to which the firewall is connected. 

  1. The following screenshot is an example of the VM properties (in VMware, right click on machine and edit settings)
    vm_int_2m.png
  2. The sys.s1.p3.hwaddr (00:50:56:a3:3c:37), shown in the screenshot below, corresponds to the configuration of the VM shown in the previous screenshot.
    See the MAC address, which Palo Alto Networks uses for ethernet1/3 that is: 12:ab:11:04:ac:12
    vm_int_1m.png
  3. Shut down the VM, switch ethernet1/3 to manual MAC and type in appropriate MAC (in this case 12:ab:11:04:ac:12):
    vm_int_3m.png
  4. Power on the VM and verify the changes:
    vm_int_4m.png
    Repeat for all interfaces that are required to work without promiscuous mode. Please note this only applies to L3 interfaces.

 

owner: rweglarz



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm2kCAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language