• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

VMware Promiscuous Mode with Cisco ASA

KapsZ28

2[H]4U
Joined
May 29, 2009
Messages
2,114
I guess this is also a networking related question. I am trying to understand when and why this would be used and what kind of impact it can cause.

In this case we have several VMs all using the same dvPortGroup with the following security settings.

Promiscuous Mode: Accept
MAC Address Changes: Accept
Forged Transmits: Accept

The majority of our other port groups have all three of those settings set to Reject.

To my knowledge the person that set this up said it was needed because of the Cisco ASA and possibly for monitoring? Not 100% sure, plus our monitoring is through SNMP.


Has anyone else dealt with something like this before? I want to make sure the settings are right. The VMs are used for RDS and I don't want performance issues or network drops because the dvPortGroup was setup incorrectly.
 
Not sure the vASA requires it..but those settings won't cause drops or performance issues. Some security issues if other VMs are connected to that same port group and you're worried about it..but that's it.
 
Basically doing this allows the ASA to have full access to the portgroup in question... meaning it takes in ALL the traffic.. Forged/Mac Changes whatever happens on that it allows/sees it on that portgroup...

Usually we only turn that stuff on all the way when we are using something like wireshark to capture packet flow traffic on a portgroup and we keep it limited because it can be subject to MITM attacks when you can see all the traffic...
 
Not sure the vASA requires it..but those settings won't cause drops or performance issues. Some security issues if other VMs are connected to that same port group and you're worried about it..but that's it.

From what I have seen a couple of places was that performance can take a hit because of the additional packets on the vSwitch. Maybe something else too.

Even this KB from VMware about network performance says to make sure promiscuous mode is not configured. http://kb.vmware.com/selfservice/mi...nguage=en_US&cmd=displayKC&externalId=1004087
 
They tell you to disable it for performance because if you enable it all frames could be seen by a guest and depending on what it's doing cause CPU use. Not a big deal in almost every case. It's best to disable it if not needed, for sure. Hit up the ASA docs to see if it's a requirement.
 
As NetJunkie said, Configuring the port group to allow all packets go to all VMs will generate more "swapping" of VMs on the host. Every time the host is ready to give the VM a network packet it needs to give it some CPU time. Just meaning, all VMs on that port group may spend more time on the CPU so the OS can reject a packet then it would normally need.

One of the things that can help with this. Create a second port group with the same vlan and name it "Monitor_SameName," configure the new port group with triple Accept, then you can place VMs into this monitor port group when they need to be monitored.

If your security group/person wants ALL packets ALL the time.... well then things get more interesting.

Some other reasons I've seen triple Accept is for Multicast requirements and for any VMs that are configured within the OS to change the packets or use a special "OS level mac address" for software Licensing. You could configure the hardware level mac address and make sure this mac address never changes on the vcenter side. The other option is to allow the OS to set the Mac address so it never changes and never requires you to "fix" mac based software licensing. Very rare cases but they do exist and do require that Special Accept setting to get it out onto the vSwitch.

Nicholas Farmer
 
Last edited:
Back
Top