Before you begin
If you require external access to VMs connected to this switch, you will be required to connect an additional physical NIC on the ESX to a physical switch.
You connect monitoring ports to standard vSwitches. When you create a standard vSwitch, ESX creates a default port group for this vSwitch. Each monitoring port in a Virtual Sensor must be connected to different port groups.
Task
-
Optionally, connect an additional physical NIC on the ESX to the adjacent physical switch.
In scenario 4, for example, you must connect an additional NIC to the corresponding physical switch.
-
Log on to the ESX as the root user in VMware vSphere Web Client.

-
On the vSphere
Home tab, select
Hosts and Clusters.

-
Select the required ESX server and select
Manage → Networking → Virtual switches.

-
Click on the
Add host networking icon.

-
In the
Select connection type section, select the required connection type and click
Next.
Selecting the connection type depends on your network design and requirements. If the VMs that will be connected to this switch do not need access outside the ESX, you might select Virtual Machine Port Group for a Standard Switch. However, for requirements as in scenario 4, it is mandatory to select Physical Network Adapter. Consider that you now select Virtual Machine Port Group for a Standard Switch.

-
For
Select target device, select
New standard switch, the required number of ports, and then click
Next.

-
Based on your network requirements, click on the
Add adapters icon and select the corresponding physical network adapter. Then click
Next.


If you select an adapter, make sure that a physical NIC corresponding to the network adapter you selected is connected to the network. -
In the
Network Label field, enter the required name for the default port group that the wizard creates for the switch.
You can modify Network Label even later. For example, you can name it as VIPS600-PG-Port1 for easier management.
-
In
VLAN ID, select
All (4095) and select
Next.
.png)
-
Click
Finish.
This vSwitch is now listed under Virtual Switches on the Networking tab.
.png)
-
Select the vSwitch that you created, move the mouse over its physical adapter, and click on it.

-
Click on the
Edit adapter speed icon.

-
Verify if the
Configured Speed, Duplex is set to
Auto negotiate.

For other property values, you can leave them with the default values.
-
Modify the security properties of the vSwitch.
-
Select the vSwitch and click on the
Edit settings icon.

-
Select
Security, make sure the fields are set to the values mentioned below, and then click
OK.
- Promiscuous mode — Reject
- MAC Address Changes — Reject
- Forged Transmits — Accept

-
Select the vSwitch and click on the
Edit settings icon.
-
Modify the security settings of the default port group.
It is assumed that you will use this port group to connect the monitoring port of a Sensor.
-
Move the mouse over the default port group and click on it.
The switch port group is now selected.

-
Click on the
Edit settings icon for the switch port group.
.png)
- Click Properties and modify the Network label, if required.
-
Make sure
VLAN ID is set to
All (4095).
This switch port group must receive all VLAN traffic similar to a trunk port.
.png)
-
Click
Security, select the
Override check box next to
Promiscuous Mode, and then select
Accept from the drop-down.
This is mandatory for the port group that you will use for any Sensor monitoring port.
.png)
-
Move the mouse over the default port group and click on it.
-
Create a new port group for the other VMs in this vSwitch.
For example, in scenario 2, this is the port group that you will use for the 10.10.10.16 server.
Note
Skip this step for scenario 4.
-
Select the corresponding vSwitch and click on the
Add host networking icon.

-
In the
Select connection type step, select
Virtual Machine Port Group for a Standard Switch and then click
Next.

-
In the
Select target device step, select
Select an existing standard switch and make sure the vSwitch that you created is selected. Then click
Next.

-
In the
Network Label field, enter the required name for the default port group that the wizard creates for the switch.
You can modify Network Label later. For example, you can name it as Server Port for easier management.
-
In the
VLAN ID (Optional) field, you can specify the required VLAN. For scenario 1, for example, select
None (0) and click
Next and then
Finish.
None (0) means that the traffic is not tagged with a VLAN.

-
Move the mouse over the switch port group and click on it.
The switch port group is now selected.

-
Click on the
Edit settings icon for the switch port group.
.png)
-
On the
Security tab, make sure the fields are set with the following values and click
OK.
- Promiscuous mode — Reject
- MAC Address Changes — Reject
- Forged Transmits — Accept

-
Select the corresponding vSwitch and click on the
Add host networking icon.
- Click OK to close the Edit settings dialog.