The UF on my test win7 box was setup correctly. The standalone was setup correctly as well. So then, I used wireshark on the test box and on the standalone to monitor the communication on both network interfaces. I looked at the UF logs too. I could see that communication back from the UF to 9997 on the standalone was failing. I went back to my standalone which resides on a linux centos vm (in vmware workstation) on a windows 7 physical box. I had opened all the splunk ports on the CentOS firewall, and configured the VMware network editor to NAT correctly. The problem was the windows OS firewall. Something caused it to change/discard port 9997. I went back into the windows fw > advanced settings > inbound rules, and added port 9997 again. Then it worked. It was a windows firewall issue.
IF anyone would like full details on how to setup a similar testing lab, then please let me know and I will provide full details regarding CentOS fw, vmware nat, windows OS firewall configurations.
Thank you for all your help.
... View more