VMware vSphere

 View Only

Promiscuous Nic monitoring 2 virtual switches?

  • 1.  Promiscuous Nic monitoring 2 virtual switches?

    Posted Dec 13, 2018 04:02 PM

    I am new to Vmware networking. I have a lab setup with a  4 Nics in my ESXi server.

    Nic 0 has a dedicated physical LAN1 with VMs. Also assigned to Virtual Switch 0 and portgroup 0

    Nic 1 is promiscuous mode and assigned to its own Vswitch and that is in turn assigned to VM with a SIEM on a physical mirror port - all working well monitoring outbound traffic on my phsyical network. Same LAN1 as Nic 0. I created a virtual switch 1 and portgroup 1 for this.(My SIEM has Nic 0 for mgmt/web interface and Nic 1 for collecting data off wire).

    Nic 2 is attached to a different physical LAN2. I have different VMs on this and firewall between LAN1 and LAN2. Virtual Switch 2 and portgroup 2.

    Is there anyway to use Nic1 to monitor traffic on LAN2? can it be part of 2 virtual switches? In the physical world, I could put a hub in the middle and plug Nic1, switch 1 and switch 2 all in together.

    It seems like i should be able to put a promiscous port on Switch 2 and somehow tie Nic1 into that too?