6.7

Table Of Contents
Tagging
Mode
VLAN ID on switch port
groups Description
EST 0 The physical switch performs the VLAN tagging. The host network adapters are
connected to access ports on the physical switch.
VST Between 1 and 4094 The virtual switch performs the VLAN tagging before the packets leave the host. The
host network adapters must be connected to trunk ports on the physical switch.
VGT
n
4095 for standard
switch
n
Range of and
individual VLANs for
distributed switch
The virtual machine performs the VLAN tagging. The virtual switch preserves the
VLAN tags when it forwards the packets between the virtual machine networking stack
and external switch. The host network adapters must be connected to trunk ports on
the physical switch.
The vSphere Distributed Switch supports a modification of VGT. For security reasons,
you can configure a distributed switch to pass only packets that belong to particular
VLANs.
Note For VGT you must have an 802.1Q VLAN trunking driver installed on the guest
operating system of the virtual machine.
Watch the video that explains the modes of VLAN tagging in virtual switches.
Modes of VLAN Tagging in vSphere
(http://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_vlan_tagging_modes)
Private VLANs
Private VLANs are used to solve VLAN ID limitations by adding a further segmentation of the logical
broadcast domain into multiple smaller broadcast subdomains.
A private VLAN is identified by its primary VLAN ID. A primary VLAN ID can have multiple secondary
VLAN IDs associated with it. Primary VLANs are Promiscuous, so that ports on a private VLAN can
communicate with ports configured as the primary VLAN. Ports on a secondary VLAN can be either
Isolated, communicating only with promiscuous ports, or Community, communicating with both
promiscuous ports and other ports on the same secondary VLAN.
To use private VLANs between a host and the rest of the physical network, the physical switch connected
to the host needs to be private VLAN-capable and configured with the VLAN IDs being used by ESXi for
the private VLAN functionality. For physical switches using dynamic MAC+VLAN ID based learning, all
corresponding private VLAN IDs must be first entered into the switch's VLAN database.
Create a Private VLAN
Create the necessary private VLANs on the vSphere Distributed Switch to be able to assign distributed
ports to participate to a private VLAN.
Procedure
1 In the vSphere Web Client, navigate to the distributed switch.
2 On the Configure tab, expandSettings and select Private VLAN .
3 Click Edit.
vSphere Networking
VMware, Inc. 141