VMware Cloud Community
sandsfootgroup
Enthusiast
Enthusiast

Is MAC address filtering Possible on Port Group?

Hi

Is it possible to apply a MAC address filter to a port group?

I'm trying to configure a specific set of known MAC addresses to be allowed to connect to specific port groups.

Thanks

Reply
0 Kudos
5 Replies
scott28tt
VMware Employee
VMware Employee

MAC addresses from outside of the host on which the VMs reside, or of the VMs themselves?

What's your use case?


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
Reply
0 Kudos
scott28tt
VMware Employee
VMware Employee

Moderator: Moved to vSphere Network Discussions


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
Reply
0 Kudos
sandsfootgroup
Enthusiast
Enthusiast

So I would like to limit which VMs on the same esxi can connect to the port group.

For example, there might be 20 VMs but I would only like 6 VMs with static MAC addresses be able to connect to "port-group-live".

Reply
0 Kudos
nachogonzalez
Commander
Commander

I don't know of any feature like that (at least on vSphere)

Thinking out loud, I would so something like this: 

1. Define a set of permissions in which only admins that know what they are doing might be able to connect VMs to other networks.
2. If this "port-group-live" is so critical, you can set the number of ports or vSwitch so I would set it as 6
 https://docs.vmware.com/en/VMware-vSphere/6.0/com.vmware.vsphere.hostclient.doc/GUID-856BBFC0-31FB-4...
3. Later, I would set Static Binding (in which the vNIC / vSwitch port binding can only change when the VM is deleted or removed)
4. Last I would set permit mac address changes/ permit forged transmits and permit promiscuous mode all to deny. 

Please let me know if that works. 

Reply
0 Kudos
sandsfootgroup
Enthusiast
Enthusiast

Hello

Thanks for the suggestion, but we aren't using distributed switches - not sure limiting the number of ports can be done on a standard switch?

Thanks

Reply
0 Kudos