The VM-Series firewall functionality is very similar
to the Palo Alto Networks hardware firewalls, but with the following
Do not use the VMware snapshots functionality on the
VM-Series on ESXi. Snapshots can impact performance and result in
intermittent and inconsistent packet loss.See the VMware best practice
recommendation for using snapshots.
need configuration backups, use Panorama, or from the firewall, use
named configuration snapshot
(Device > Set up > Operations).
Export named configuration snapshot
the firewall’s active configuration (
and allows you to save it to any network location.
Dedicated CPU cores are recommended.
High Availability (HA) Link Monitoring is not supported on
VM-Series firewalls on ESXi. Use Path Monitoring to verify connectivity
to a target IP address or to the next hop IP address.
Up to 10 total ports can be configured; this is a VMware
limitation. One port is used for management traffic and up to 9
can be used for data traffic.