Modifying a VLAN ID on an active vSphere management interface (vmknic) or virtual machine port group can result in an immediate loss of host connectivity, disconnection from vCenter Server inventory, and a disruption to running virtual machine network paths if applied incorrectly.This article outlines the safe procedure for updating the VLAN ID across standard or distributed switch infrastructure.
VMware vSphere ESXi 7.x, 8.x, 9.x
VMware vCenter Server 7.x, 8.x, 9.x
Improper modification of network properties on virtual switches without ensuring upstream physical switch tag alignment or local switch redundancy paths leads to administrative lockouts.
NOTE: Upstream physical switch ports (ToR switches) must be configured for the new VLAN tags (Trunk or Access mode) before altering virtual switch configuration to prevent a total loss of connectivity.
To prevent locking yourself out of the ESXi host during a management network migration, temporarily move the management VMkernel adapter (vmk0) to a standard switch. This ensures a localized network restore can be performed natively via the console if upstream or virtual center configuration connectivity fails.
Log into the vSphere Client.
Follow the documentation to migrate vmk0 and an assigned physical network adapter (uplink) away from the vSphere Distributed Switch: Migrate Virtual Machines (VMs) and VMkernel Adapters from Distributed Switch (vDS) to Standard Switch (vSS).
Ensure management connectivity remains functional via the temporary vSS before continuing.
In the vSphere Client, navigate to the Networking inventory view.
Locate the target Management Distributed Virtual Switch (vDS) and select the original Management Distributed Portgroup.
Right-click the portgroup and select Edit Settings.
Navigate to VLAN and modify the configuration to the desired new VLAN ID. Click OK.
Note: Ensure this new VLAN is tagged correctly on the vDS portgroup across all inventory instances before proceeding.
Establish a direct remote console session (KVM/IPMI/iLO/iDRAC) to the physical ESXi host.
Press F2 and log into the Direct Console User Interface (DCUI).
Navigate to Configure Management Network and select Network Adapters to ensure the appropriate interface is designated.
Select VLAN (optional).
Modify the configuration to the desired new VLAN ID and press Enter.
Press ESC to exit. When prompted to save changes and restart the management network, select Y (Yes).
Optional: If network parameters fail to apply cleanly to the interface, restart the ESXi host to reinitialize the network stack configuration with the new VLAN parameters.
Repeat these sub-steps for all remaining ESXi hosts in the cluster.
Once management connectivity is validated under the new VLAN ID across all hosts, log back into the vSphere Client.
Migrate the management infrastructure and uplinks from the temporary vSS back to the primary vDS by referencing: Migrating from Standard to Distributed vSwitch.
Navigate to the ESXi host > Configure > Networking > Virtual switches.
Find the target Virtual Machine Port Group and click Edit.
Modify the VLAN ID field to match the new destination segment. Click OK.
Select the Networking tab from the vSphere Client sidebar.
Expand your Distributed Switch and click on the target Distributed Port Group.
Go to Configure > Properties > Edit.
Under the VLAN section, update the VLAN ID value.
Click OK. The modification immediately applies to all virtual machines connected to this distributed port group across all cluster hosts.