Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ESXi Won't boot PfSense /w passthrough

    Scheduled Pinned Locked Moved Virtualization
    18 Posts 3 Posters 6.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      well from your picture your pfsense wan vmnic2 is not connected..  So that is going to be an issue, same with vmnic3

      How told you it was more secure and less latency?  The basis of the whole concept is to let esxi control the physical nics..

      So here is my esxi network.  See attached

      See how pfsense (pfsense-vm) has interface in the 4 segments.  Wan, Lan, WLAN and DMZ (does not have physical connection only VMs)

      Pfsense handles the routing between segments and firewall rules between them.  So off the wan vswitch you see it connect to vmnic3 which is connected to my modem only. Off the Lan vswitch I have vmnic2 which is connected to my real world physical switch this allows both VMs and real machines to talk to each other on this segment.  Off the wlan vswitch is vmnic0 which is connected to different switch that has my AP and printer (ease of wireless to access the printer via airprint, etc.) and my wireless controller - that unifi-linux vm.

      I then have my vmkern (esxi managment interface) connected to vmnic1, which is also connected to my lan physical switch.  I broke this out on its on physical nic because for 1 I had a spare nic :)  And 2 vmkern takes a bit of a performance hit when sharing nic with other vms.  My transfers to and from the datastore are now faster - but this is not really a big deal and can go either way - if you have spare nic then sure break it out.  if you want to be more secure put it on its own managment segment where you have your managment station, etc.

      Then there is the DMZ vswitch - this is not connected to the real world, and only VMs are use here - internet and other segments can talk to them via pfsense routing and firewall.

      Why do you have yoru windows VMs on their own switch and physical nic - this should be your lan, and pfsense should have an interface it.  And your physical network should be connected to this.  Along with your vmkern.

      In your setup how do you get to windows vms without being physically connected to that vmnic?

      esxinetworksetup.png
      esxinetworksetup.png_thumb

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • M
        mysongranhills
        last edited by

        I was just going to run ethernet from ESXi management interface to a real life switch (also connected to PfSense LAN ), although I admit your way makes more sense now that I see/understand it.

        It shows as disconnected in my picture b/c nothing is currently connected. During all my testing it was connected.

        So any idea at all why all my interfaces stop responding after 30-60 minutes time???? Until i fix this not much else matters :(

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          so the physical stops working?  Your setup is not a viable option as you posted so its hard for me to speculate what could be the problem

          So your picture pfsense doesn't do anything.. Is there a physical switch that connects vmnic0 and 3? What does vmnic2 connect too?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • M
            mysongranhills
            last edited by

            I think your misunderstanding me. My set-up works fine…..for 30-60 minutes. Right now I'm just trying to get PfSense working at all. So for testing purposes PfSense's LAN port connects directly to a dell laptop (192.168.1.5), WAN port connects directly to cable modem.

            Whats not viable about it? I will definitely switch things up once I get it working and have it take over routing from my Asus router.

            my picture doesnt show that I plan on connectting a gigabit switch to PfSense's LAN port (and then a wifi access point to the switch). This is how I plan to connect all my stuff to the internet. I realise right now none of my VM's are routing through PfSense. This is b/c I can't keep PfSense working and they need internet. So they are hooked into my asus router for now.

            vmnic3 will eventually connect to real switch, right now dell laptop is connected. Right now vmnic2 unused.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              your vms are not connected to the pfsense lan network - unless you have some physical switch connecting those physical nics?  Makes no sense to go from virtual to physical, back in physical to virtual again.  Connect your VMs to the pfsense lan vswitch.

              So maybe this helps I added part of my physical network and how it connects to the esxi host nics

              Drawing1.jpg
              Drawing1.jpg_thumb

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • M
                mysongranhills
                last edited by

                @johnpoz:

                your vms are not connected to the pfsense lan network - unless you have some physical switch connecting those physical nics?

                So maybe this helps I added part of my physical network and how it connects to the esxi host nics

                I think you might have missed my previous post were I explained my setup a little better.
                @mysongranhills:

                I think your misunderstanding me. My set-up works fine…..for 30-60 minutes. Right now I'm just trying to get PfSense working at all. So for testing purposes PfSense's LAN port connects directly to a dell laptop (192.168.1.5), WAN port connects directly to cable modem.

                Whats not viable about it? I will definitely switch things up once I get it working and have it take over routing from my Asus router.

                my picture doesnt show that I plan on connectting a gigabit switch to PfSense's LAN port (and then a wifi access point to the switch). This is how I plan to connect all my stuff to the internet. I realise right now none of my VM's are routing through PfSense. This is b/c I can't keep PfSense working and they need internet. So they are hooked into my asus router for now.

                vmnic3 will eventually connect to real switch, right now dell laptop is connected. Right now vmnic2 unused.

                Does that make sense?

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  ah ok – so it works for 30 60 mins and then what errors do you get?  You just loose your wan connection?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • M
                    mysongranhills
                    last edited by

                    @johnpoz:

                    ah ok – so it works for 30 60 mins and then what errors do you get?  You just loose your wan connection?

                    Pretty much. No errors in PfSense VM console still shows LAN IP as 192.168.1.1 WAN shows no ip and pings from 192.168.1.5 to 192.168.1.1 come back as timed out or destination unreachable. When 5 minutes earlier WAN had IP pings to LAN int. came back <1ms. Nothing done in PfSense other then boot it up.

                    1 Reply Last reply Reply Quote 0
                    • M
                      mysongranhills
                      last edited by

                      Does any one know what  logs I can check and what I should be looking for? Is this problem I'm having not that common?

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        you can look in pfsense system log, clearly it would report loss of wan IP..  But seems more like problem with your esxi box if you can not ping the lan IP?  Does esxi show the nics active.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • M
                          mysongranhills
                          last edited by

                          I haven't checked PfSense logs yet b/c I now believe it to be a ESXi issue. Once all the connections dropped I checked the vSwitch and it shows the physical NICs as disconnected for LAN and WAN vSwitches. NIC lights still blinking and laptop still shows connected on ethernet.

                          Any idea what could be causing this?

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            This is suppose to be only have upgrade adding, etc.. but you could try this

                            http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2019871

                            What specific build of esxi are you running.  Current build is 2143827 and was just released the other day.

                            I would also check your logs, the logs are in /var/log – enable shell on your esxi host and check them out

                            http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2032076
                            Location of ESXi 5.1 and 5.5 log files (2032076)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • M
                              mysongranhills
                              last edited by

                              @johnpoz:

                              This is suppose to be only have upgrade adding, etc.. but you could try this

                              http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2019871

                              What specific build of esxi are you running.  Current build is 2143827 and was just released the other day.

                              I would also check your logs, the logs are in /var/log – enable shell on your esxi host and check them out

                              http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2032076
                              Location of ESXi 5.1 and 5.5 log files (2032076)

                              Thx. I think I'm on build 16xxxxx. Will update to latest build tonight when I get home and try moving NIC to another PCI-E slot.  Could this be a bad NIC ?

                              Worst case scenario can I use my unused onboard NIC port for WAN and just add use existing VM network for Pfsense LAN?

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by

                                Build  1623387?  That is Update 1, way back in March..  Yeah I would update lots of changes and fixes and drivers updated, etc.

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.