I migrated a vm from a host without vshield installed to another host with vshield installed. After the vmotion, I lost all pings to the vm.
any idea? I do not have firewall enabled but vshield is installed on the destination host.
Have you applied any security rule on the vShiled App firewall? You can verify this configuration on the vShield Manager web admin > Datacenters Folder > DatacenterName > App Firewall tab.
i checked and there is only 1 default rule any any any allow
On the detsination host are the appropriate VLANs configured both in the ESXi host and the physical switch the host connects to?
Check the Network security settings, the MAC address, Forged transmit as well. Once I faced this type of issue and had to make changes in VMX file with the same MAC address showing in the console.
If you have checked this, then it is fine, try migrating back to any host which don't have vshield installed to confirm the issue with the vshield policy.
found out the issue and it was vshield app causing the problem. I have 3 host cluster and one of them does not have vshield app. So vmotioning to that host works. but after vmotioning to another will not.
But I have a default rule to allow access and not block. So I had to manually add the vm into the protection exclusion list before networking will work for this vm. Still dont understand why I had to put the vm into the exclusion list