Search the VMware Knowledge Base (KB)
View by Article ID

How promiscuous mode works at the virtual switch and portgroup levels (1002934)

  • 100 Ratings

Details

Promiscuous mode is a security policy which can be defined at the virtual switch or portgroup level in vSphere ESX/ESXi. A virtual machine, Service Console or VMkernel network interface in a portgroup which allows use of promiscuous mode can see all network traffic traversing the virtual switch.

By default, a guest operating system's virtual network adapter only receives frames that are meant for it. Placing the guest's network adapter in promiscuous mode causes it to receive all frames passed on the virtual switch that are allowed under the VLAN policy for the associated portgroup. This can be useful for intrusion detection monitoring or if a sniffer needs to analyze all traffic on the network segment.

For more information on configuring a virtual switch or portgroup to allow promiscuous mode, see Configuring promiscuous mode on a virtual switch or portgroup (1004099).


Solution

When promiscuous mode is enabled at the portgroup level, objects defined within that portgroup have the option of receiving all incoming traffic on the vSwitch. Interfaces and virtual machines within the portgroup will be able to see all traffic passing on the vSwitch, but all other portgroups within the same virtual switch do not.

When promiscuous mode is enabled at the virtual switch level, all portgroups within the vSwitch will default to allowing promiscuous mode. However, promiscuous mode can be explicitly disabled at one or more portgroups within the vSwitch, which override the vSwitch-defined default.

If software within a virtual machine is attempting to put the guest network adapter in promiscuous mode, contrary to the defined vSwitch or portgroup security policy, it may be necessary to investigate if the virtual machine is running undesired software. For more information, see Identifying virtual machines attempting to use promiscuous network mode on ESX/ESXi (1023341).

Additional Information

For translated versions of this article, see:

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 100 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.

What can we do to improve this information? (4000 or fewer characters)




Please enter the Captcha code before clicking Submit.
  • 100 Ratings
Actions
KB: