Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Multicast MAC Addresses in VMware vSwitches

Posted on 2016-09-25
3
Medium Priority
?
175 Views
Last Modified: 2016-10-05
Hello,

We have 5 ESX Servers and vCenter server, both version 5.5. We use standard vSwitches on each ESX server and a bond (with 2 physical ethernet ports) on each server that we use to pass traffic for various VLANs.

I noticed that network packets sent to a multicast destination MAC addresss, are flooded to all the VMs connected to the same vSwitch on the same host.

Is there a way to configure the VMs or the vSwitch, so that packets sent to a particular multicast MAC address will be delivered only to some of the VMs? i.e. to assign a second MAC address on a VM via CLI, apart from the primary MAC assigned to the VM? or maybe we can achieve this by using a distributed virtual switch instead of the standard vSwitch?

We need multicast traffic for various clusters of systems (servers, firewalls, etc), so we can't really avoid it.

Thanks,
0
Comment
Question by:Harrris
  • 2
3 Comments
 
LVL 125
ID: 41814733
I noticed that network packets sent to a multicast destination MAC addresss, are flooded to all the VMs connected to the same vSwitch on the same host.

This is correct, and they will also be sent out to other ports, on physical switches and devices.

Is this causing you an issue ?

This is why some organisation disable multicast, because the are paranoid, that it impacts services!
0
 

Author Comment

by:Harrris
ID: 41815018
Not causing a particular problem but since some of this traffic carries sensitive data, I'm wondering if there is a way to avoid this. Can we configure the hypervisor to deliver packets for a particular MAC address only to a specific VM?
0
 
LVL 125

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 41815027
Can we configure the hypervisor to deliver packets for a particular MAC address only to a specific VM?

There are no options within ESXi networking, to prevent traffic leaving a VM, and multicasting to other network ports.
0

Featured Post

Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

571 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question