If you plan to connect a monitoring port to an existing vSwitch, you might have to modify some of the configuration. For example, in scenario 2, you need to modify virtual switch 1 to connect it to monitoring port 1.
Steps:
Log on to the ESX as the root user in VMware vSphere Web Client.
.png)
Select the required ESX server and select Configure → Networking → Virtual switches.
.png)
Select the required vSwitch and click on the EDIT tab.
Go to Security section, make sure the fields are set to the values mentioned below, and click OK.
Promiscuous mode — Accept
MAC Address Changes — Accept
Forged Transmits — Accept
Note
Select the Override check-box to be able to change the state of an option.
.png)
Modify the port group that you are using for the VMs in this switch.
For example, in scenario 2, this is the port group that you use for the 10.10.10.15 client.
Note
This step might be relevant only for scenario 2.
Scroll down to the required switch and click the ellipsis icon next to the switch port group that you created and click Edit Settings.
.png)
In the Properties section, modify the Network label if required.
In the VLAN ID (Optional) field, you can specify the required VLAN. For the scenarios in this section, select All (4095).
.png)
Go to Security section make changes in the fields as per your requirement, and click OK. In this scenario, the following settings have been implemented:
Promiscuous mode — Accept
MAC address changes — Accept
Forged transmits — Accept
Note
Select the Override check-box to be able to change the state of an option.
.png)
Create a port group to connect the monitoring port of a Sensor.
Scroll to the corresponding vSwitch, expand the node, and click the ADD NETWORKING tab.
In the Select connection type section, select Virtual Machine Port Group for a Standard Switch and click NEXT.
.png)
In the Select target device section, select Select an existing standard switch and make sure the vSwitch that you created is selected. Then, click NEXT.
.png)
In the Network Label field, enter the required name
For example, enter VIPS Client Port.
Make sure VLAN ID is set to All (4095), click NEXT and then FINISH.
.png)
Scroll down to the switch where the switch port group has been created, click the ellipsis icon next to it and click Edit Settings.
In this example, it is VIPS Client Port.
.png)
In the Security section, make sure the fields are set with the following values, and click OK.
Promiscuous mode — Accept
MAC Address Changes — Accept
Forged Transmits — Accept
Note
Select the Override check-box to be able to change the state of an option.
This setting is mandatory for the port group that you will use for any Sensor monitoring port.
.png)