Control how inbound and outbound frames for a dvPort are handled by editing the Security policies.

To edit the Security policies on an individual dvPort, the associated dvPort group must be set to allow policy overrides.


Log in to the vSphere Client and display the vNetwork Distributed Switch.


On the Ports tab, right-click the port to modify and select Edit Settings.


Click Policies.

By default, Promiscuous Mode is set to Reject, and MAC Address Changes and Forged Transmits are set to Accept.


In the Security group, select whether to reject or accept the security policy exceptions.



Promiscuous Mode - Reject

Has no effect on which frames are received by the guest adapter.

Promiscuous Mode - Accept

The guest adapter detects all frames passed on the vSwitch that are allowed under the VLAN policy for the port group that the adapter is connected to.

MAC Address Changes - Reject

If the guest OS changes the MAC address of the adapter to anything other than what is in the .vmx configuration file, all inbound frames are dropped.

If the guest OS changes the MAC address back to match the MAC address in the .vmx configuration file, inbound frames are sent again.

MAC Address Changes - Accept

If the MAC address from the guest OS changes, frames to the new MAC address are received.

Forged Transmits -Reject

Outbound frames with a source MAC address that is different from the one set on the adapter are dropped.

Forged Transmits - Accept

No filtering is performed, and all outbound frames are passed.


Click OK.