To setup properly the portgroups in VMware vSwitching environment, we had to create two portgroups per vSwitch as depicted below:
Reason for this configuration is that “operative portgroups” where servers and machines are connected should not be in Promiscuous mode to avoid sniffing other machines’ traffic, while portgroups dedicated to IPS inline ports must:
- be configured in promiscuous mode to receive all traffic of the vSwitch they are connected to
- be part of VLAN ID 4095 to “pass” all VLAN IDs to Virtual Machine without any intervention
Below you can find the sample screenshot about where to configure these settings:
These settings can be done in portgroups’ properties in ESX and they are NOT needed if you implement similar configuration in VMWare Workstation or VMWare Free Server.


Recent Comments