The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a standard vSwitch for a monitoring port

Prev Next

Prerequisites:

If you require external access to VMs connected to this switch, you will be required to connect an additional physical NIC on the ESX to a physical switch.

You connect monitoring ports to standard vSwitches. When you create a standard vSwitch, ESX creates a default port group for this vSwitch. Each monitoring port in a Virtual Sensor must be connected to different port groups.

Steps:

  1. Optionally, connect an additional physical NIC on the ESX to the adjacent physical switch.

    In scenario 4, for example, you must connect an additional NIC to the corresponding physical switch.

  2. Log on to the ESX as the root user in VMware vSphere Web Client.

    GUID-ED003931-0EA0-43A9-889D-8C1D10FE78FE-low.png
  3. Select the required ESX server and select Configure → Networking → Virtual switches.

    GUID-EFF4167D-2437-4338-AD0F-88BB19DB084F-low.png
  4. Click the ADD NETWORKING tab.

    GUID-9C2905C6-4F52-437C-B44B-A4EAC1142E7A-low.png
  5. In the Select connection type section, select the required connection type and click NEXT.

    Selecting the connection type depends on your network design and requirements. If the VMs that will be connected to this switch do not need access outside the ESX, you might select Virtual Machine Port Group for a Standard Switch. However, for requirements as in scenario 4, it is mandatory to select Physical Network Adapter. Consider that you now select Virtual Machine Port Group for a Standard Switch.

    GUID-50D4ADF6-8172-4560-9729-1748EB9B3580-low.png
  6. In the Select target device section, select New standard switch and set the value of MTU (Bytes) (here, 1500). Click NEXT.

    GUID-6D547674-1AA5-40D0-9BA5-79BDFDD56ABB-low.png
  7. Based on your network requirements, click on the Add adapters (+) icon and select the corresponding physical network adapter. Then click NEXT.

    GUID-5203E505-F148-484F-8D6F-639203DFD455-low.pngGUID-A20B93EA-C4F5-490D-8359-CBDF6C022EF6-low.png

    If you select an adapter, make sure that a physical NIC corresponding to the network adapter you selected is connected to the network.

  8. In the Network Label field, enter the required name for the default port group that the wizard creates for the switch.

    You can modify Network Label even later. For example, you can name it as VIPS5000-PG-Port1 for easier management.

  9. In the VLAN ID drop-down, select All (4095) and click NEXT.

    GUID-769DA301-B1A0-4166-B50C-4526DF11C977-low.png
  10. Click FINISH.

    This port group is now listed under the Virtual Switch.

    GUID-E6072B56-9F54-4DBF-8C87-36DF9A2739B3-low.png
  11. Navigate to Configure → Networking → Physical adapters and verify if Configured Speed of the assigned physical adapter is set to Auto negotiate.

    GUID-A566D0A4-F630-42D8-ACE7-3098009A2615-low.png

    For other property values, you can leave them with the default values.

  12. Modify the security properties of the vSwitch.

    1. Scroll down to the newly created switch, and click the EDIT tab.

    2. Go to Security section, make sure the fields are set to the values mentioned below, and then click OK.

      • Promiscuous mode — Accept

      • MAC Address Changes — Accept

      • Forged Transmits — Accept

      Note

      Select the Override check-box to be able to change the state of an option.

      GUID-384FACB1-DEEB-42EE-BD83-67320AB1F101-low.png
  13. Modify the security settings of the default port group.

    It is assumed that you will use this port group to connect the monitoring port of a Sensor.

    1. Under the newly created switch, click on the ellipsis icon next to the switch port group that you created and click Edit Settngs.

      GUID-AEF5C9E8-4C87-44FA-A8D9-F3F354ECB66F-low.png
    2. In the Properties section, modify the Network label, if required.

    3. Make sure VLAN ID is set to All (4095).

      This switch port group must receive all VLAN traffic similar to a trunk port.

      GUID-DF6E8700-9B1C-474E-89B0-8CC80251D14F-low.png
    4. Go to the Security section, make sure the fields are set with the following values and click OK.

      • Promiscuous mode — Accept

      • MAC Address Changes — Accept

      • Forged Transmits — Accept

        Note

        Select the Override check-box to be able to change the state of an option.

      This is mandatory for the port group that you will use for any Sensor monitoring port.

      GUID-1B3781EF-D814-4AA5-B25B-7287AE437605-low.png
  14. Create a new port group for the other VMs in this vSwitch.

    For example, in scenario 2, this is the port group that you will use for the 10.10.10.16 server.

    Note

    Skip this step for scenario 4.

    1. Expand the corresponding vSwitch node and click the ADD NETWORKING tab.

      The Add Networking wizard appears.

    2. In the Select connection type section, select Virtual Machine Port Group for a Standard Switch and click NEXT.

      GUID-A4513C6A-2FDD-4B4C-974C-16ACCEC84857-low.png
    3. In the Select target device section, select Select an existing standard switch and make sure the vSwitch that you created is selected. Then click NEXT.

      GUID-915A769D-9E5F-4373-A7C4-BD45939817E5-low.png
    4. In the Connection settings section, enter the required name in the Network Label field for the default port group that the wizard creates for the switch. For example, you can name it as Server Port Group for easier management.

      You may modify Network Label later.

    5. In the VLAN ID (Optional) field, you can specify the required VLAN. For scenario 1, for example, select None (0) and click Next and then, click FINISH.

      None (0) means that the traffic is not tagged with a VLAN.

      GUID-99F8785B-0EE5-4A55-B70A-10507EF9BF1F-low.png
    6. Under the respective switch node, click the ellipsis icon next to the switch port group (Server Port Group) that you created and select Edit Settngs.

      GUID-BF0528EE-5757-44DE-BAB0-9620AAC41764-low.png
    7. Go to the Security section, make sure the fields are set with the following values and click OK.

      • Promiscuous mode — Accept

      • MAC Address Changes — Accept

      • Forged Transmits — Accept

        Note

        Select the Override check-box to be able to change the state of an option.

      GUID-077DF669-4642-4EB9-AF30-27215F1FF9B5-low.png
  15. Click OK to close the Edit settings wizard.