6.5.1

Table Of Contents
4 Reject or accept promiscuous mode activation or MAC address changes in the guest operating
system of the virtual machines attached to the standard switch or port group.
Option Description
Promiscuous mode
n
Reject. The VM network adapter receives only frames that are addressed to
the virtual machine.
n
Accept.The virtual switch forwards all frames to the virtual machine in
compliance with the active VLAN policy for the port to which the VM network
adapter is connected.
Note Promiscuous mode is insecure mode of operation. Firewalls, port
scanners, intrusion detection systems, must run in promiscuous mode.
MAC address changes
n
Reject. If the guest OS changes the effective MAC address of the virtual
machine to a value that is different from the MAC address of the VM network
adapter (set in the .vmx configuration file), the switch drops all inbound
frames to the adapter.
If the guest OS changes the effective MAC address of the virtual machine
back to the MAC address of the VM network adapter, the virtual machine
receives frames again.
n
Accept. If the guest OS changes the effective MAC address of the virtual
machine to a value that is different from the MAC address of the VM network
adapter, the switch allows frames to the new address to pass.
Forged transmits
n
Reject. The switch drops any outbound frame from a virtual machine adapter
with a source MAC address that is different from the one in the .vmx
configuration file.
n
Accept. The switch does not perform filtering, and permits all outbound
frames.
5 Click OK.
Configure the Security Policy for a Distributed Port Group or
Distributed Port
Set a security policy on a distributed port group to allow or reject promiscuous mode and MAC address
changes from the guest operating system of the virtual machines associated with the port group. You can
override the security policy inherited from the distributed port groups on individual ports.
Prerequisites
To override a policy on distributed port level, enable the port-level override option for this policy. See
Configure Overriding Networking Policies on Port Level.
Procedure
1 In the vSphere Web Client, navigate to the distributed switch.
vSphere Networking
VMware, Inc. 111