6.7

Table Of Contents
Prerequisites
To override a policy on distributed port level, enable the port-level override option for this policy. See
Configure Overriding Networking Policies on Port Level.
Procedure
1 In the vSphere Web Client, navigate to the distributed switch.
2 Navigate to the monitoring policy for the distributed port group or distributed port.
Option Action
Distributed port group a From the Actions menu, select Distributed Port Group > Manage
Distributed Port Groups.
b Select Monitoring.
c Select the port group and click Next.
Distributed port a On the Networks tab, click Distributed Port Groups and double-click a
distributed port group .
b On the Ports tab, select a port and click the Edit distributed port settings
icon.
c Select Monitoring.
d Select Override next to the properties to override.
3 From the NetFlow drop-down menu, enable or disable NetFlow and click Next.
4 Verify your settings and apply the configuration.
Trac Filtering and Marking Policy
In a vSphere distributed switch, by using the traffic filtering and marking policy, you can protect the virtual
network from unwanted traffic and security attacks or apply a QoS tag to a certain type of traffic.
The traffic filtering and marking policy represents an ordered set of network traffic rules for security and
for QoS tagging of the data flow through the ports of a distributed switch. In general, a rule consists of a
qualifier for traffic, and of an action for restricting or prioritizing the matching traffic.
The vSphere distributed switch applies rules on traffic at different places in the data stream. The
distributed switch applies traffic filter rules on the data path between the virtual machine network adapter
and distributed port, or between the uplink port and physical network adapter for rules on uplinks.
Trac Filtering and Marking on a Distributed Port Group or Uplink
Port Group
Set traffic rules at the level of distributed port groups or of uplink port groups to introduce filtering and
priority tagging for traffic access over virtual machines, VMkernel adapters, or physical adapters.
n
Enable Traffic Filtering and Marking on a Distributed Port Group or Uplink Port Group
Enable the traffic filtering and marking policy on a port group if you want to configure traffic security
and marking on all virtual machine network adapters or uplink adapters that are participating in the
group.
vSphere Networking
VMware, Inc. 114