After installing and configuring a Palo Alto Firewall VM as a "Bump on the Wire" Traffic fails to pass.
ESX all versions
vCenter all versions
When the Firewall was deployed on two virtual switches, the traffic passing out the second "bump" interface has a different MAC than the vNIC MAC for the virtual machine.
To resolve this issues configure the virtual switch port policy as follows:
For information Forged transmits and MAC address changes see: