6.0

Table Of Contents
Prerequisites
To override the VLAN policy at the port level, enable the port-level overrides. See “Edit Advanced
Distributed Port Group Settings,” on page 44.
Procedure
1 Log in to the vSphere Client and select the Networking inventory view.
2 Select the vSphere distributed switch in the inventory pane.
3 On the Ports tab, right-click the port to modify and select Edit Settings.
4 Under Policies, select VLAN and click Override.
5 Type a VLAN trunk range to propagate to the physical network adapter.
For trunking of several ranges and individual VLANs, separate the entries with commas.
6 Click OK.
Security Policy
Networking security policy provides protection of traffic against MAC address impersonation and
unwanted port scanning
The security policy of a standard or distributed switch is implemented in Layer 2 (Data Link Layer) of the
network protocol stack. The three elements of the security policy are promiscuous mode, MAC address
changes, and forged transmits. See the vSphere Security documentation for information about potential
networking threats.
Edit Security Policy for a vSphere Standard Switch
You can edit Layer 2 security policies, such as MAC address changes and forged transmits, for a vSphere
standard switch.
Layer 2 is the data link layer. The three elements of the Layer 2 Security policy are promiscuous mode, MAC
address changes, and forged transmits. In non-promiscuous mode, a guest adapter listens to traffic only on
its own MAC address. In promiscuous mode, it can listen to all the packets. By default, guest adapters are
set to non-promiscuous mode.
You can override the switch-level settings for individual standard port groups by editing the settings for the
port group.
For more information about security, see the vSphere Security documentation.
Prerequisites
Launch the vSphere Client and log in to a vCenter Server system.
Procedure
1 Log in to the vSphere Client and select a host in the inventory pane.
2 Click the Configuration tab and click Networking.
3 Click Properties for the standard switch whose Layer 2 Security policy you want to edit.
4 In the Properties dialog box for the standard switch, click the Ports tab.
5 Select the standard switch item and click Edit.
6 Click the Security tab.
Chapter 22 Networking Policies
VMware, Inc. 269