{"id":3301,"date":"2018-10-28T17:22:54","date_gmt":"2018-10-28T04:22:54","guid":{"rendered":"http:\/\/www.zoyinc.com\/?p=3301"},"modified":"2018-11-16T21:47:11","modified_gmt":"2018-11-16T08:47:11","slug":"sonicwall-vlan-to-private-physical-interface","status":"publish","type":"post","link":"http:\/\/www.zoyinc.com\/?p=3301","title":{"rendered":"SonicWall VLAN to private physical interface"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3324\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet11.jpg\" alt=\"\" width=\"1500\" height=\"334\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet11.jpg 1500w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet11-150x33.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet11-300x67.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet11-768x171.jpg 768w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet11-500x111.jpg 500w\" sizes=\"auto, (max-width: 1500px) 100vw, 1500px\" \/><\/p>\n<p>I had a Windows 10 VM, running inside VMware ESXi 6.0, which I needed to connect to the laptop as shown in the above diagram. In addition I needed both the laptop and VM to be on an isolated LAN which meant neither the VM nor laptop to should be able to access the internet or our LAN &#8211; or indeed anything else.<\/p>\n<p>Typically the situation to this problem would be to have two physical NICs, <strong>N<\/strong>etwork <strong>I<\/strong>nterface <strong>C<\/strong>ard, on the ESX server with one NIC connected to the LAN for ESX management and the other NIC connected to the laptop via a dedicated switch. However in my case I was going to have trouble actually plugging in another network card, as ESX was running on a small form fact PC &#8211; Lenovo M58P. In addition the ESX serverwas in the garage where it was going to be difficult to run another network cable to it.<\/p>\n<p>The solution was to connect the VM to a VLAN, inside ESX, and connect this to my SonicWall. This is the same way that I connected my web server to the internet &#8211; see my post: <a  href=\"http:\/\/www.zoyinc.com\/?p=2596\">Public facing web server on SonicWALL VLAN<\/a><\/p>\n<p>In this case I could not use the DMZ zone because I didn&#8217;t want either the VM nor the laptop to have internet access plus I didn&#8217;t actually want it in the DMZ as this exists for the like of public web servers that might be the subject of an attack.<\/p>\n<h2>What I did<\/h2>\n<p>Within ESX I created a &#8220;Port Group&#8221; which I called &#8220;HomeRun&#8221; and configured it to use VLAN ID 15:<a  href=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet03.jpg\" class=\"thickbox no_icon\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3310\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet03.jpg\" alt=\"\" width=\"643\" height=\"361\" \/><\/a>I setup the NIC for the VM to connect to the &#8220;HomeRun&#8221; ESX network:<\/p>\n<p><a  href=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet02.jpg\" class=\"thickbox no_icon\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3309\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet02.jpg\" alt=\"\" width=\"409\" height=\"324\" \/><\/a>ESX has a &#8220;Management Network&#8221; port group, which is somewhat like a virtual interface. This is what the ESX vSphere client connects to or from ESX v6. 5 and above this is where you point your browser to in order to manage ESX:<a  href=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06.jpg\" class=\"thickbox no_icon\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3315 size-full\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06.jpg\" alt=\"\" width=\"789\" height=\"508\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06.jpg 789w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06-150x97.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06-300x193.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06-768x494.jpg 768w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet06-466x300.jpg 466w\" sizes=\"auto, (max-width: 789px) 100vw, 789px\" \/><\/a>By putting our VM on a VLAN it means that it&#8217;s network traffic is isolated from the LAN &#8211; VLAN = &#8220;<strong>V<\/strong>irtual&#8221; LAN. So in our case this means that our VM is on one LAN and ESX management is on another LAN but all done with one single NIC on the ESX host. Works great, but leaves us with the challenge of connecting the VLAN\/VM to a physical isolated Ethernet port on the SonicWall.<\/p>\n<p>Next step was on the SonicWall where I create a new zone, under &#8220;Network | Zones&#8221;, as follows:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3313\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet05.jpg\" alt=\"\" width=\"353\" height=\"394\" \/><\/p>\n<p>Next I created a &#8220;Virtual Interface&#8221; on the X0 interface in SonicWall. Remember that the X0 interface is the primary LAN interface and also where our switch connects to the SonicWall. So from &#8220;Network | Interfaces&#8221; select:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3318\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet07.jpg\" alt=\"\" width=\"323\" height=\"122\" \/><\/p>\n<p>Then set this up thus:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3319\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet09.jpg\" alt=\"\" width=\"356\" height=\"305\" \/><\/p>\n<p>Now we have to configure the X4 interface, where the laptop is plugged in, to connect to see the VM. So in &#8220;Network | Interfaces&#8221; edit the X4 interface to be:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3320\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet10.jpg\" alt=\"\" width=\"310\" height=\"237\" \/><\/p>\n<h2>Routing<\/h2>\n<p>It is important to understand how things are routed. The current setup has<\/p>\n<p>The VM has the following config:<\/p>\n<pre class=\"crayon:false;\">Windows IP Configuration\r\n\r\nHost Name . . . . . . . . . . . . : Win10A\r\nPrimary Dns Suffix . . . . . . . :\r\nNode Type . . . . . . . . . . . . : Hybrid\r\nIP Routing Enabled. . . . . . . . : No\r\nWINS Proxy Enabled. . . . . . . . : No\r\n\r\nEthernet adapter Ethernet0:\r\n\r\nConnection-specific DNS Suffix . :\r\nDescription . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection\r\nPhysical Address. . . . . . . . . : 00-0C-29-12-EA-11\r\nDHCP Enabled. . . . . . . . . . . : No\r\nAutoconfiguration Enabled . . . . : Yes\r\nLink-local IPv6 Address . . . . . : fe80::74dd:5518:4469:1771%5(Preferred)\r\nIPv4 Address. . . . . . . . . . . : 192.168.213.66(Preferred)\r\nSubnet Mask . . . . . . . . . . . : 255.255.255.0\r\nDefault Gateway . . . . . . . . . : <span style=\"background-color: #ffff00;\">192.168.213.1<\/span>\r\nDHCPv6 IAID . . . . . . . . . . . : 100666409\r\nDHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-2E-B6-97-00-0C-29-12-EA-11\r\nDNS Servers . . . . . . . . . . . : 8.8.8.8\r\nNetBIOS over Tcpip. . . . . . . . : Enabled<\/pre>\n<p>The laptop is configured:<\/p>\n<pre class=\"crayon:false;\">Windows IP Configuration\r\n\r\nHost Name . . . . . . . . . . . . : Finn\r\nPrimary Dns Suffix . . . . . . . :\r\nNode Type . . . . . . . . . . . . : Hybrid\r\nIP Routing Enabled. . . . . . . . : No\r\nWINS Proxy Enabled. . . . . . . . : No\r\n\r\nEthernet adapter Ethernet:\r\n\r\nConnection-specific DNS Suffix . :\r\nDescription . . . . . . . . . . . : Intel(R) 82567LM Gigabit Network Connection\r\nPhysical Address. . . . . . . . . : 78-E7-D1-AF-EB-33\r\nDHCP Enabled. . . . . . . . . . . : No\r\nAutoconfiguration Enabled . . . . : Yes\r\nLink-local IPv6 Address . . . . . : fe80::7183:b94c:318c:d324%4(Preferred)\r\nIPv4 Address. . . . . . . . . . . : 192.168.211.44(Preferred)\r\nSubnet Mask . . . . . . . . . . . : 255.255.255.0\r\nDefault Gateway . . . . . . . . . : <span style=\"background-color: #ffff00;\">192.168.211.1<\/span>\r\nDHCPv6 IAID . . . . . . . . . . . : 58255313\r\nDHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1F-2B-1D-4F-78-E7-D1-AF-EB-33\r\nDNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1\r\nfec0:0:0:ffff::2%1\r\nfec0:0:0:ffff::3%1\r\nNetBIOS over Tcpip. . . . . . . . : Enabled<\/pre>\n<p>As you know that the VM is on the &#8220;X0:V15&#8221; interface under X0 and it has an IP of &#8220;192.168.213.1&#8221;<\/p>\n<p>The laptop is on the X4 interface which has an IP of &#8220;192.168.211.1&#8221;.<\/p>\n<p>The important thing here is the configuration of the gateway for the VM and the laptop so that the packets for the other end are directed through the appropriate gateway<\/p>\n<p>Obviously it is vital that both the &#8220;X0:V15&#8221; and &#8220;X4&#8221; interfaces are on the same zone &#8211; in this case &#8220;Test&#8221;<\/p>\n<h2>Challenges and things to watch out for<\/h2>\n<p>During this exercise I had a lot of challenges. Frequently my diagnostic methods didn&#8217;t always go to plan. Typically I would try to ping something, like the laptop and it would fail. I would assume that the problem was my SonicWall setup but in actual fact it was because the Windows firewall on the laptop, thinking it was in a public area, would drop all pings.<\/p>\n<p>For for both the VM and the laptop I turned off the firewall while I was doing the setup and diagnostics &#8211; you <strong>may<\/strong> want to enable the firewalls when finished ?<\/p>\n<p>Likewise I would try to ping the gateway in the Sonicwall and the ping would not return. However the problem was that the interface in SonicWall did not have &#8220;ping&#8221; enabled:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3312\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2018\/10\/VLAN2Ethernet04.jpg\" alt=\"\" width=\"419\" height=\"320\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Testing of the complete solution<\/h2>\n<p>I have tested the above configuration and from the VM I can RDP to the laptop and from the laptop I can RDP to the VM.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I had a Windows 10 VM, running inside VMware ESXi 6.0, which I needed to connect to the laptop as shown in the above diagram. In addition I needed both the laptop and VM to be on an isolated LAN which meant neither the VM nor laptop to should be able to access the internet [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3322,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[124,58,345],"tags":[343,342,352,458,459,346,353,372,308],"class_list":["post-3301","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-esxi","category-how-to","category-sonicwall","tag-esx","tag-esxi","tag-firewall","tag-interface","tag-networking","tag-sonicwall","tag-vlan","tag-vm","tag-vmware"],"_links":{"self":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts\/3301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3301"}],"version-history":[{"count":13,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts\/3301\/revisions"}],"predecessor-version":[{"id":3325,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts\/3301\/revisions\/3325"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/media\/3322"}],"wp:attachment":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3301"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}