Control how inbound and outbound frames for a dvPort group are handled by editing the Security policies.


In the vSphere Client, display the Networking inventory view and select the dvPort group.


From the Inventory menu, select Network > Edit Settings.


In the Properties dialog box for the port group, click the Security tab.

By default, Promiscuous Mode is set to Reject. MAC Address Changes and Forged Transmits are set to Accept.

The policy exception overrides any policy set at the vSwitch level.


In the Policy Exceptions pane, select whether to reject or accept the security policy exceptions.

Policy Exceptions




Promiscuous Mode

Placing a guest adapter in promiscuous mode has no effect on which frames are received by the adapter.

Placing a guest adapter in promiscuous mode causes it to detect all frames passed on the vSwitch that are allowed under the VLAN policy for the port group that the adapter is connected to.

MAC Address Changes

If the guest OS changes the MAC address of the adapter to anything other than what is in the .vmx configuration file, all inbound frames are dropped.

If the guest OS changes the MAC address back to match the MAC address in the .vmx configuration file, inbound frames are sent again.

If the MAC address from the guest OS changes, frames to the new MAC address are received.

Forged Transmits

Outbound frames with a source MAC address that is different from the one set on the adapter are dropped.

No filtering is performed, and all outbound frames are passed.


Click OK.