i might be able to help with this.
i have vmware running with agnitum well, in the normal Rules mode.
here is what i had to do:
In agnitum options, System tab, Rules:
I added a RULE that said to allow all traffic in and out from the particular ip that my vmware runs as
(ie on my lan its 192.168.0.5).
note that this is not an APPLICATION RULE, but rather a SYSTEM RULE.
this works perfectly and everything else stays tight as a drum (note that you can also run an independent firewall on the virtual operating system to block incoming and outgoing traffic from WITHIN the vmware).
one caveat:
in the past (haven't checked recently), i had to DISABLE this system rule when i tried things like running an ftp server on my main machine. just something to be aware of if you have troubles in this regard.