vSwitch Promiscuous Mode Accept / Reject
Hi
In a Plant we have ESXI with four vlan ( Area 1 Path0/1 and Area 20 Path0/1).
Does anyone know how we have to set the Promiscuous Mode on the vSwitch?
I didn't found any Information in 3BSE056141-600 B.
Thx
In a Plant we have ESXI with four vlan ( Area 1 Path0/1 and Area 20 Path0/1).
Does anyone know how we have to set the Promiscuous Mode on the vSwitch?
I didn't found any Information in 3BSE056141-600 B.
Thx
Answers
To configure a portgroup or virtual switch to allow promiscuous mode:
- Log into the ESXi/ESX host or vCenter Server using the vSphere Client.
- Select the ESXi/ESX host in the inventory.
- Click the Configuration tab.
- In the Hardware section, click Networking.
- Click Properties of the virtual switch for which you want to enable promiscuous mode.
- Select the virtual switch or portgroup you wish to modify and click Edit.
- Click the Security tab.
- From the Promiscuous Mode dropdown menu, click Accept.
Leave it at Default, which would be "Reject". This how we have it configured.
See VMware KB 1004099 how to set.
See VMware KB 1004099 how to set.
Thats the Question, Agree or Reject?!
As far as I can tell, 800xA does not need Promiscuous Mode to operate. Usually, only network sniffing software need this security impeeding permission. Asset Optimization may have something like a network analyzer feature I can’t recollect right now. Such node/function may need to enter promiscuous mode to operate properly.
Also, never mix primary and secondary paths of any RNRP network on the same media (cable, interface, etc). Always keep them on separate wires/fibres.
VLAN tagging is OK per se, but do not let primary and secondary of same RNRP Area share same Ethernet Interface anywhere on your networks.
One of the principal ideas of RNRP redundancy is ample isolation between primary and secondary network paths. For example, a network loop/storm on primary may disturb secondary if they share same media anywhere on the networks.
Also, never mix primary and secondary paths of any RNRP network on the same media (cable, interface, etc). Always keep them on separate wires/fibres.
VLAN tagging is OK per se, but do not let primary and secondary of same RNRP Area share same Ethernet Interface anywhere on your networks.
One of the principal ideas of RNRP redundancy is ample isolation between primary and secondary network paths. For example, a network loop/storm on primary may disturb secondary if they share same media anywhere on the networks.
Add new comment