6.0

Table Of Contents
7 In the Policy Exceptions pane, select whether to reject or accept the security policy exceptions.
Table 223. Policy Exceptions
Mode Reject Accept
Promiscuous Mode Placing a guest adapter in
promiscuous mode has no effect on
which frames are received by the
adapter.
Placing a guest adapter in
promiscuous mode causes it to detect
all frames passed on the standard
switch that are allowed under the
VLAN policy for the port group that
the adapter is connected to.
MAC Address Changes If the guest OS changes the MAC
address of the adapter to anything
other than what is in the .vmx
configuration file, all inbound
frames are dropped.
If the guest OS changes the MAC
address back to match the MAC
address in the .vmx configuration
file, inbound frames are sent again.
If the MAC address from the guest
OS changes, frames to the new MAC
address are received.
Forged Transmits Outbound frames with a source
MAC address that is different from
the one set on the adapter are
dropped.
No filtering is performed, and all
outbound frames are passed.
8 Click OK.
Edit the Security Policy for a Distributed Port Group
You can set a security policy on a distributed port group to override the policy set for the distributed switch.
The three elements of the Security policy are promiscuous mode, MAC address changes, and forged
transmits.
In nonpromiscuous mode, a guest adapter listens to traffic only on its own MAC address. In promiscuous
mode, it can listen to all the packets. By default, guest adapters are set to non-promiscuous mode.
Prerequisites
Launch the vSphere Client and log in to a vCenter Server system.
Procedure
1 Log in to the vSphere Client and select the Networking inventory view.
2 Right-click the distributed port group in the inventory pane, and select Edit Settings.
3 Select Policies.
By default, Promiscuous Mode is set to Reject. MAC Address Changes and Forced Transmits are set
to Accept.
Chapter 22 Networking Policies
VMware, Inc. 271