VMware Cloud Community
Brandon7a
Contributor
Contributor
Jump to solution

Enabling Promiscuous Mode on a vswitch

I am creating a new VM....Cisco ISE 3300. In the instructions, it tells me to make sure Promiscuous Mode is enabled on the vswitch. If I enable this, will it screw up any of my other VM's that are currently using this switch? I'm using vCenter 5.0 with ESXi 4.1

Thanks

Tags (3)
Reply
0 Kudos
1 Solution

Accepted Solutions
weinstein5
Immortal
Immortal
Jump to solution

No it should not - you can also create a seperate virtual machine port group and just enable promiscous mode for that port group and not set it for the entire vswitch

If you find this or any other answer useful please consider awarding points by marking the answer correct or helpful

View solution in original post

Reply
0 Kudos
8 Replies
weinstein5
Immortal
Immortal
Jump to solution

No it should not - you can also create a seperate virtual machine port group and just enable promiscous mode for that port group and not set it for the entire vswitch

If you find this or any other answer useful please consider awarding points by marking the answer correct or helpful
Reply
0 Kudos
Brandon7a
Contributor
Contributor
Jump to solution

Is it true that it doesn't effect anything if the vswitch is set to Promiscuous mode b/c Promiscuous mode also needs to be set on the adapter as well?

Reply
0 Kudos
kjb007
Immortal
Immortal
Jump to solution

Making that change at the vSwitch level, allows the switch to accept promisc mode requests from the adapters themselves.  The NICs on the guests have to enable it as well, in order to listen for packets.

You can mitigate this by creating another portgroup on the same VLAN, if you have VLANs configured, and enabling promisc mode on that as mentioned above.

-KjB

vExpert/VCP/VCAP vmwise.com / @vmwise -KjB
Brandon7a
Contributor
Contributor
Jump to solution

How do I enable it on the NICs?

Reply
0 Kudos
kjb007
Immortal
Immortal
Jump to solution

That's an OS task.  There's no enabling, as such, from the virtualization side, other than allowing it at the vswitch level.  From there, the OS controls putting the vNIC into promisc mode.

-KjB

vExpert/VCP/VCAP vmwise.com / @vmwise -KjB
Reply
0 Kudos
Brandon7a
Contributor
Contributor
Jump to solution

One last question concerning promiscuious mode. I do plan on creating a separate port group but lets say I enable it at the switch level, what if any effect will this have on my VMs that are on that vswitch? Could it create any issues?

Thanks

Reply
0 Kudos
kjb007
Immortal
Immortal
Jump to solution

No issues, per se.  If the os puts the nic into promisc mode, then you will be able to see more traffic, but no ill effects.

-KjB

vExpert/VCP/VCAP vmwise.com / @vmwise -KjB
rickardnobel
Champion
Champion
Jump to solution

Brandon wrote:

I do plan on creating a separate port group but lets say I enable it at the switch level, what if any effect will this have on my VMs that are on that vswitch? Could it create any issues?

If you enable Promiscous Mode at the vSwitch level then one potential issue is that every VM could (if they want) see all other VMs traffic, as the Promiscous setting more or less turns the switch port into a hub port. Depending on your enviroment this could be a security problem.

My VMware blog: www.rickardnobel.se
Reply
0 Kudos