Configuring layer two VM as inline IPS in VMware ESX
November 19th, 2008 | by RoarinPenguin |
To setup properly the portgroups in VMware vSwitching environment, we had to create two portgroups per vSwitch as depicted below:
Reason for this configuration is that “operative portgroups” where servers and machines are connected should not be in Promiscuous mode to avoid sniffing other machines’ traffic, while portgroups dedicated to IPS inline ports must:
be configured in promiscuous mode to receive all traffic of the vSwitch they are connected to
be part of VLAN ID 4095 to “pass” all VLAN IDs to Virtual Machine without any intervention