When you use a virtual distributed switch (vDS), you have the ability to block traffic through traffic filtering and marking. This allows you to secure your virtual machines and/or services at the virtual network level rather than using third-party software on your virtual machines or virtual servers.
To enable traffic filtering and marking on VMware vCenter Server (VCSA) 6.7, select the desired port group (distributed or uplink) and go to: Configure -> Settings -> Traffic filtering and marking.
As you can see, by default, traffic filtering and marking is turned off.
To activate it, first click on the button: Enable and reorder.
In the “Enable and Reorder Traffic Rules” window that appears, click on the “Enable all traffic rules” switch so that it appears green.
Then click OK.
Note that you can change the order of the traffic rules later if you wish by using the "Move Up" and "Go Down" buttons which are grayed out at the moment.
For this tutorial, we will create a traffic rule to block ping (whose associated protocol is: ICMP).
As you can see, in our case we have a distributed virtual switch "MyDSwitch" with a distributed port group "DPortGroup_VMs" where we have just enabled traffic filtering and marking and to which our virtual machines are connected under Windows 10.
However, at the moment there are no defined traffic rules. So everything is allowed.
The 1st virtual machine on Windows 10 has the IP address: 10.0.0.21.
The 2nd virtual machine on Windows 10 has the IP address: 10.0.0.22.
As you can see, for the moment, ping works between our 2 virtual machines on Windows 10.
To block some network traffic, select the desired port group and return to: Configure -> Settings -> Traffic filtering and marking.
As you can see, the message “Traffic filtering and marking is Turned ON” appears.
Click: Add.
In the “New Traffic Rule” window that appears, you can specify:
To block ping, configure the traffic rule like this:
Then click OK.
The created traffic rule appears.
As you can see, ping no longer works between our 2 virtual machines on Windows 10.
As the ping command tells you, the 4 packets sent were lost.
VMware 1/13/2023
VMware 8/12/2022
VMware 7/31/2024
VMware 10/4/2024
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
You must be logged in to post a comment