The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a standard vSwitch for a monitoring port

Prev Next

Before you begin

If you require external access to VMs connected to this switch, you will be required to connect an additional physical NIC on the ESX to a physical switch.

You connect monitoring ports to standard vSwitches. When you create a standard vSwitch, ESX creates a default port group for this vSwitch. Each monitoring port in a Virtual Sensor must be connected to different port groups.

Task

  1. Optionally, connect an additional physical NIC on the ESX to the adjacent physical switch.
    In scenario 4, for example, you must connect an additional NIC to the corresponding physical switch.
  2. Log on to the ESX as the root user in VMware vSphere Web Client.


  3. On the vSphere Home tab, select Hosts and Clusters.


  4. Select the required ESX server and select Manage → Networking → Virtual switches.


  5. Click on the Add host networking icon.


  6. In the Select connection type section, select the required connection type and click Next.
    Selecting the connection type depends on your network design and requirements. If the VMs that will be connected to this switch do not need access outside the ESX, you might select Virtual Machine Port Group for a Standard Switch. However, for requirements as in scenario 4, it is mandatory to select Physical Network Adapter. Consider that you now select Virtual Machine Port Group for a Standard Switch.

  7. For Select target device, select New standard switch, the required number of ports, and then click Next.


  8. Based on your network requirements, click on the Add adapters icon and select the corresponding physical network adapter. Then click Next.




    If you select an adapter, make sure that a physical NIC corresponding to the network adapter you selected is connected to the network.
  9. In the Network Label field, enter the required name for the default port group that the wizard creates for the switch.
    You can modify Network Label even later. For example, you can name it as VIPS600-PG-Port1 for easier management.
  10. In VLAN ID, select All (4095) and select Next.


  11. Click Finish.
    This vSwitch is now listed under Virtual Switches on the Networking tab.

  12. Select the vSwitch that you created, move the mouse over its physical adapter, and click on it.


  13. Click on the Edit adapter speed icon.


  14. Verify if the Configured Speed, Duplex is set to Auto negotiate.


    For other property values, you can leave them with the default values.

  15. Modify the security properties of the vSwitch.
    1. Select the vSwitch and click on the Edit settings icon.


    2. Select Security, make sure the fields are set to the values mentioned below, and then click OK.
      • Promiscuous mode — Reject
      • MAC Address Changes — Reject
      • Forged Transmits — Accept


  16. Modify the security settings of the default port group.
    It is assumed that you will use this port group to connect the monitoring port of a Sensor.
    1. Move the mouse over the default port group and click on it.
      The switch port group is now selected.

    2. Click on the Edit settings icon for the switch port group.


    3. Click Properties and modify the Network label, if required.
    4. Make sure VLAN ID is set to All (4095).
      This switch port group must receive all VLAN traffic similar to a trunk port.

    5. Click Security, select the Override check box next to Promiscuous Mode, and then select Accept from the drop-down.
      This is mandatory for the port group that you will use for any Sensor monitoring port.

  17. Create a new port group for the other VMs in this vSwitch.
    For example, in scenario 2, this is the port group that you will use for the 10.10.10.16 server.

    Note

    Skip this step for scenario 4.

    1. Select the corresponding vSwitch and click on the Add host networking icon.


    2. In the Select connection type step, select Virtual Machine Port Group for a Standard Switch and then click Next.


    3. In the Select target device step, select Select an existing standard switch and make sure the vSwitch that you created is selected. Then click Next.


    4. In the Network Label field, enter the required name for the default port group that the wizard creates for the switch.
      You can modify Network Label later. For example, you can name it as Server Port for easier management.
    5. In the VLAN ID (Optional) field, you can specify the required VLAN. For scenario 1, for example, select None (0) and click Next and then Finish.
      None (0) means that the traffic is not tagged with a VLAN.

    6. Move the mouse over the switch port group and click on it.
      The switch port group is now selected.

    7. Click on the Edit settings icon for the switch port group.


    8. On the Security tab, make sure the fields are set with the following values and click OK.
      • Promiscuous mode — Reject
      • MAC Address Changes — Reject
      • Forged Transmits — Accept


  18. Click OK to close the Edit settings dialog.