vSphere vNetwork

 View Only
  • 1.  Is MAC address filtering Possible on Port Group?

    Posted Nov 10, 2020 10:59 AM

    Hi

    Is it possible to apply a MAC address filter to a port group?

    I'm trying to configure a specific set of known MAC addresses to be allowed to connect to specific port groups.

    Thanks



  • 2.  RE: Is MAC address filtering Possible on Port Group?

    Broadcom Employee
    Posted Nov 10, 2020 12:51 PM

    MAC addresses from outside of the host on which the VMs reside, or of the VMs themselves?

    What's your use case?



  • 3.  RE: Is MAC address filtering Possible on Port Group?

    Broadcom Employee
    Posted Nov 10, 2020 12:52 PM

    Moderator: Moved to vSphere Network Discussions



  • 4.  RE: Is MAC address filtering Possible on Port Group?

    Posted Nov 10, 2020 01:55 PM

    So I would like to limit which VMs on the same esxi can connect to the port group.

    For example, there might be 20 VMs but I would only like 6 VMs with static MAC addresses be able to connect to "port-group-live".



  • 5.  RE: Is MAC address filtering Possible on Port Group?

    Posted Nov 10, 2020 02:47 PM

    I don't know of any feature like that (at least on vSphere)

    Thinking out loud, I would so something like this: 

    1. Define a set of permissions in which only admins that know what they are doing might be able to connect VMs to other networks.
    2. If this "port-group-live" is so critical, you can set the number of ports or vSwitch so I would set it as 6
     https://docs.vmware.com/en/VMware-vSphere/6.0/com.vmware.vsphere.hostclient.doc/GUID-856BBFC0-31FB-4AC1-9E1D-48DBE468E95B.html
    3. Later, I would set Static Binding (in which the vNIC / vSwitch port binding can only change when the VM is deleted or removed)
    4. Last I would set permit mac address changes/ permit forged transmits and permit promiscuous mode all to deny. 

    Please let me know if that works. 



  • 6.  RE: Is MAC address filtering Possible on Port Group?

    Posted Mar 10, 2021 12:11 PM

    Hello

    Thanks for the suggestion, but we aren't using distributed switches - not sure limiting the number of ports can be done on a standard switch?

    Thanks