14
VM-Series
Deployment
Guide
Install a VM-Series firewall on VMware vSphere Hypervisor (ESXi)
Set Up a VM-Series Firewall on an ESXi Server
Step 2
Before deploying the OVF template, set
up virtual standard switch(es) and virtual
distributed switch(es) that you will need
for the VM-Series firewall.
If you are deploying the
VM-Series firewall with layer 2,
virtual wire, or tap interfaces, any
attached virtual switch must allow
the following modes (set to
Accept):
– Promiscuous mode
– MAC address changes
– Forged transmits
– For details, see the network
interface requirements in
Requirements
.
To configure a virtual standard switch to receive frames for the
VM-Series firewall:
1.
Configure a virtual standard switch from the vSphere Client by
navigating to
Home > Inventory > Hosts and Clusters
.
2.
Click the
Configuration
tab and under
Hardware
click
Networking
.
For each VM-Series firewall attached virtual
switch, click on
Properties
.
3.
Highlight the virtual switch and click
Edit
. In the vSwitch
properties, click the
Security
tab and set
Promiscuous Mode,
MAC Address Changes
and
Forged Transmits
to
Accept
and
then click
OK
. This change will propagate to all port groups on
the virtual switch.
To configure a virtual distributed switch to receive frames for
the VM-Series firewall:
1.
Select
Home > Inventory > Networking
. Highlight the
Distributed Port Group
you want to edit and select the
Summary
tab.
2.
Click
Edit Settings
and select
Policies > Security
and set
Promiscuous Mode, MAC Address Changes
and
Forged
Transmits
to
Accept
and then click
OK
.
Provision a VM-Series Firewall (Continued)