Link to home
Start Free TrialLog in
Avatar of skiaholic
skiaholicFlag for Liechtenstein

asked on

VMWare Workstation Firewall

Hallo,
I have installed VMWare Workstation 7 on Windows Server 2008, Bridged Network connection, everything runs fine. Now I have to close all ports but one (svn 3690) on the VMs (Win XP), what I did with some Firewall-tools installed on the VMs directly, but this is quite complex to administer and can be turned off by admin-users on the VM.

Is there a possibility to set up the firewall for the Bridged Network of Workstation directly? I tried to set up the firewall on the host (Windows 2008), but these settings were then not for the VMs as they have an own, fixed IP.

Thank you for helping.
SOLUTION
Avatar of bgoering
bgoering
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
There are other virtual router firewalls you can also look at such as PFsense or Vyatta, they also have free editions like monowall - I use monowall extensively myself so that one always comes to mind first.
Avatar of skiaholic

ASKER

Thank you for this tip, I've just installed monowall as a VM in Workstation now, trying to set it up. But something seems wrong I think with my monowall-inside network configuration or the host-only VMnet1.

monowall
- WAN set to a fixed IP of my subnet, gateway same as the old VM
- LAN set to fixed IP of my subnet
- Network Adapter 1 to VMnet0 (bridged to uplink)
- Network Adapter 2 to VMnet1 (host-only)

new VM
- Network Adapter set to VMnet1 (host-only)
- a fixed IP of my subnet, gateway the monowall-LAN
- can't ping gateway


no changes on host-network and the old VM is still running bridged fully connected to outside. Any idea what I could have done wrong?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Looks like just switch NA1 to host-only and NA2 to briddged should do it
I tried that before, then I can't connect to webGui anymore (from host). switching it back it connects again.
.To connect from the host you will need to make sure your host only networking is what vmware workstation is expecting. In my case (see screen shot) my VMnet1 host only is on 192.168.142.0.

Now if you go into Network properties you will find the Workstation has assigned to the NIC it created for VMnet1 an IP4 address of x.x.x.1 - in my case 192.168.142.1.

You should assign monowall something like x.x.x.5 (.5 is what I use, but anything other than .1 will work) then you will be able to manage it from the host.

Now on your VM setup networking as x.x.x.whatever and make the gateway x.x.x.5

Your WAN address on the monowall will be whatever your vm address was while it was bridged.

Hope this helps
Hallo, thank you for support until now, in the last weeks I could not have a look at this topic because of other things. Now I have set up a monowall-VM and a WinXP-VM. I setup the firewall rules and this works all (I can connect from WinXP to outside and bloc ports in monowall).

Now only one problem: I want to connect to the WinXP-VM from outside. From my idea this would work with the IP of monowall-VM (WAN-address), and forward the port to the IP of WinXP-VM (mine 192.168.0.2), I'm using Radmin right now.

It doesn't work. I can't ping monowall-WAN-IP. Any idea why? Thanks for your help!!
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Finally, everything works as the idea was at the beginning. Thanks very much for your help and patience!