VMware Cloud Community
hpatelaumtech
Contributor
Contributor

No Network between Cisco 1120 and Virtual Switch

Dear Community Support,

I have installed ESXI version 7.02 on one of my Dell 740 server. It has 8 Physical NIC on the back (vmnic0-vmnic7).

vmnic0 is working fine as it is connected to cisco switch (Firewall-->Switch)

I have a need to create a DMZ environment - hence I created a network between my cisco firewall 1120 (Physical Port 1/7 - 192.168.3.2) and vmnic1 (192.168.3.3). Note vmnic0 is assigned to Cisco Switch which provides the 10.0.0.0/24 network.

Issue - There is No ping between 192.168.3.2 and 192.168.3.3. There is physical network cable connected between them.

Both the NIC are functional in their own side. Cisco Firewall is sending ARP for 198.168.3.3 but there is no response.

I created following on VMware:

Port Group: VM Network 192, created vSwitch192 and VLAN ID 192, It displays MAC address and lights is green in Hypervisor. On Virtual Machines as well - both adapters "Network adapter 1" and "Network adapter 2" are displayed as connected. "ifconfig" also shows both adapters and mac addresses respectively. I have kept default settings in "VM Network 192" configurations - I tried changing some parameters but no luck.

On Cisco Firewall Interface 1/7 is assigned the IP address 192.168.3.2. As mentioned above I want to create a DMZ - so I need 2 network to communicate.

Can anyone suggest if I am doing anything fundamentally wrong or give any guidance?

Thank you

Harshal

0 Kudos
2 Replies
a_p_
Leadership
Leadership

Can you confirm that on the Cisco side this is a tagged (802.1Q) port, with VLAN 192 allowed?

If it is an access port, or the default VLAN on this port is 192, you must not enter the VLAN-ID on the ESXi port group.

André

hpatelaumtech
Contributor
Contributor

Hello Mr Moderator.

Appreciate your quick and accurate response. As suggested - what I did was I created a Sub Interface under the Main Interface and transfered the static IP from Main to Sub Interface on Cisco Firepower 1120. It had a category to specify VLAN ID = 192. Doing this I was able to ping between these two interface. Note vSwitch also had VLAN ID of 192.

Next I will see how my application behaves and all traffic back and forth is fine.

Again thanks for your reply & thanks for helping

 

0 Kudos