BFE/WFP and VMNAT
I have been working to resolve an issue with VMware Server and Windows 7 for about a month now. I have determined that BFE/WFP are the root cause of myissues. When I create a VM within VMware I can ping anything I want (google.com, yahoo.com, internal, intranet, etc.), but any higher level traffic (http, https, telnet, smtp, etc.) fails. I have done numerous traffic captures between VM and physical networks. Recently I have been paying more attention to BFE and WFP and started noticing 5152 erros logged in the security logs. Below is an example of the blocked packet log: The Windows Filtering Platform has blocked a packet.Application Information:Process ID: 0Application Name: -Network Information:Direction: InboundSource Address: 91.189.88.140Source Port: 80Destination Address: 192.168.225.101Destination Port: 49643Protocol: 6Filter Information:Filter Run-Time ID: 66338Layer Name: TransportLayer Run-Time ID: 13Immediately preceeding this block is the following log:The Windows Filtering Platform has permitted a connection.Application Information:Process ID: 244Application Name: \device\harddiskvolume1\windows\system32\vmnat.exeNetwork Information:Direction: OutboundSource Address: 192.168.225.101Source Port: 49643Destination Address: 91.189.88.140Destination Port: 80Protocol: 6Filter Information:Filter Run-Time ID: 66181Layer Name: ConnectLayer Run-Time ID: 48So I have proven that the packet is coming out of the VM and being properly handled by VMNAT. For some reason, BFE is not allowing the return packet. I have tried disabling BFE, modifying firewall policies, and everything I can think of to open up the filter all to no effect.Anyone else have any ideas on how to stop BFE from blocking these valid packets?
May 11th, 2009 4:42am

We do not support virtual machine issues with Windows 7 in this forum. You may want to seek support from VMWare on such issues.
Free Windows Admin Tool Kit Click here and download it now
June 30th, 2009 7:27pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics