Sample configuration of virtual switch VLAN tagging (VST Mode)
search cancel

Sample configuration of virtual switch VLAN tagging (VST Mode)


Article ID: 311540


Updated On:


VMware vCenter Server VMware vSphere ESXi


This article provides a sample network configuration for isolation and segmentation of virtual machine network traffic.


VMware ESX Server 3.0.x
VMware vSphere ESXi 7.0.0
VMware vCenter Server 6.0.x
VMware ESXi 3.5.x Installable
VMware vCenter Server 5.5.x
VMware ESX Server 3.5.x
VMware vSphere ESXi 6.5
VMware ESXi 3.5.x Embedded
VMware vCenter Server 5.1.x
VMware vSphere ESXi 5.5
VMware vSphere ESXi 5.0
VMware ESXi 4.0.x Embedded
VMware VirtualCenter 2.0.x
VMware ESXi 4.1.x Installable
VMware ESXi 4.0.x Installable
VMware vSphere ESXi 6.0
VMware ESXi 4.1.x Embedded
VMware vCenter Server 5.0.x
VMware ESX 4.0.x
VMware vSphere ESXi 7.0.x
VMware VirtualCenter 2.5.x
VMware vCenter Server 4.1.x
VMware vCenter Server 4.0.x
VMware vSphere ESXi 5.1
VMware ESX 4.1.x


To configure Virtual Switch (vSwitch) VLAN Tagging (VST) on an ESXi/ESX host:
  1. Assign a VLAN to a portgroup(s). The supported VLAN range is 1-4094.
    Reserved VLAN IDs:
    • VLAN ID 0 (zero) Disables VLAN tagging on port group (EST Mode)
    • VLAN ID 4095 Enables trunking on port group (VGT Mode)
  2. Set the switch NIC teaming policy to Route based on originating virtual port ID (this is set by default).

To configure the physical switch settings:
  1. Define ESXi/ESX VLANs on the physical switch.
  2. Allow the proper range to the ESXi/ESX host.
  3. Set the physical port connection between the ESXi/ESX host and the physical switch to TRUNK mode. ESXi/ESX only supports IEEE 802.1Q (dot1q) trunking.
    • Physical switch is set to TRUNK mode
    • dot1q encapsulation is enabled
    • Spanning-tree is set to portfast trunk (for example, port forwarding, skips other modes)
    • Define VLAN interface
    • Assign IP Range to VLAN interface
    • VLAN Routing – and VLAN Isolation

      Caution: Native VLAN ID on ESXi/ESX VST Mode is not supported. Do not assign a VLAN to a port group that is same as the native VLAN ID of the physical switch. Native VLAN packets are not tagged with the VLAN ID on the outgoing traffic toward the ESXi/ESX host. Therefore, if the ESXi/ESX host is set to VST mode, it drops the packets that are lacking a VLAN tag.

This sample is a supported Cisco Trunk Port configuration:
interface GigabitEthernet1/2
switchport (Set to layer 2 switching)
switchport trunk encapsulation dot1q (ESXi/ESX only supports dot1q, not ISL)
switchport trunk allowed vlan 10-100 (Allowed VLAN to ESXi/ESX. Ensure ESXi/ESX VLANs are allowed)
switchport mode trunk (Set to Trunk Mode)
switchport nonegotiate (DTP is not supported)
no ip address
no cdp enable (ESXi/ESX 3.5 or higher supports CDP)
spanning-tree portfast trunk (Allows the port to start forwarding packets immediately on linkup)

Note: For more information on configuring your physical network switch, contact your switch vendor.

To assign a VLAN to a port group, there must be a corresponding VLAN interface for each VLAN on a physical switch with a designated IP range.
For example:

interface Vlan200
ip address (This IP can be used as VLAN 200 Gateway IP)

Note: When the VLAN ID is defined on the physical switch, it can be configured for ESX. If the IP range is assigned to a VLAN, decide if any routing may be required to reach other nodes on the network.

To configure a VLAN on the portgroup using the VMware Infrastructure/vSphere Client:
  1. Click the ESXi/ESX host.
  2. Click the Configuration tab.
  3. Click the Networking link.
  4. Click Properties.
  5. Click the virtual switch / portgroups in the Ports tab and click Edit.
  6. Click the General tab.
  7. Assign a VLAN number in VLAN ID (optional).
  8. Click the NIC Teaming tab.
  9. From the Load Balancing dropdown, choose Route based on originating virtual port ID.
  10. Verify that there is at least one network adapter listed under Active Adapters.
  11. Verify the VST configuration using the ping command to confirm the connection between the ESXi/ESX host and the gateway interfaces and another host on the same VLAN.

    Note: For additional information on VLAN configuration of a VirtualSwitch (vSwitch) port group, see Configuring a VLAN on a portgroup (1003825). and VLAN configuration on virtual switches, physical switches, and virtual machines (1003806)
To configure via the command line:
esxcfg-vswitch -p "portgroup_name" -v VLAN_ID virtual_switch_name

Note: The illustration attached to this article is a sample VST mode topology and configuration with two ESXi/ESX hosts, each with two NICs connecting to the Cisco switch.

Additional Information

For related information, see the VMware ESX Server 3 802.1Q VLAN Solutions white paper.

For translated versions of this article, see: Configuring a VLAN on a portgroup
Sample configuration of EtherChannel / Link Aggregation Control Protocol (LACP) with ESXi/ESX and Cisco/HP switches
Issue between VLAN interfaces in VLAN trunk mode using Intel NIC 82599 under SR-IOV scenario
Exemplo de configuração de marcação de VLAN do Virtual Switch (Modo VST)
Ejemplo de configuración para el etiquetado VLAN del conmutador virtual (modo VST)
虚拟交换机 VLAN 标记(VST 模式)的配置示例
仮想スイッチ VLAN タギング (VST Mode) のサンプル構成


1004074_VSTmode.bmp get_app