You can edit Layer 2 security policies, such as MAC address changes and forged transmits, for a vSphere standard switch.
Layer 2 is the data link layer. The three elements of the Layer 2 Security policy are promiscuous mode, MAC address changes, and forged transmits. In non-promiscuous mode, a guest adapter listens to traffic only on its own MAC address. In promiscuous mode, it can listen to all the packets. By default, guest adapters are set to non-promiscuous mode.
You can override the switch-level settings for individual standard port groups by editing the settings for the port group.
For more information about security, see the vSphere Security documentation.