VMware Cloud Community
mqzd23
Enthusiast
Enthusiast
Jump to solution

Force frame to leave ESXi server

vSphere 6.5

I'm implementing mac based acl's on our physical switch to prevent traffic from vm to vm in the same vlan. The acl's don't seem to work and i think i found the culprit: the vm's are connected to the same vlan & vswitch. The ESXi hosts observes this, the frames never leave the host to physical switch and the vswitch takes care of the communication.....correct? If correct, is there any way to force the frames to leave the host and go to the physical switch?

note: I don't have any free physical nics and although we're using a paid version (Essentials license), our license doesn't allow us to use distributed vSwitches.

Thanks in advance.

1 Solution

Accepted Solutions
daphnissov
Immortal
Immortal
Jump to solution

Correct, VM traffic that is on the same port group on the same host is "dark" to external infrastructure. I don't think there's a way to force this to egress the host to be switched and return. You're trying to implement poor-man's NSX here, because this is what NSX is exactly designed to do and does it extremely well.

View solution in original post

2 Replies
daphnissov
Immortal
Immortal
Jump to solution

Correct, VM traffic that is on the same port group on the same host is "dark" to external infrastructure. I don't think there's a way to force this to egress the host to be switched and return. You're trying to implement poor-man's NSX here, because this is what NSX is exactly designed to do and does it extremely well.

mqzd23
Enthusiast
Enthusiast
Jump to solution

Ok thanks Smiley Happy. Wouldn't say poor-man's NSX, just a different approach.

Switched strategy now: seperate vlan for every VM which allows me to do ip based ACL's.

0 Kudos