This article clarifies the default security posture and functional design of vSphere Distributed Switch (vDS) Uplink Port Groups. Administrators often observe that default uplink port groups are configured for VLAN trunking with a range of 0–4094. This configuration is a standard architectural requirement for traffic transport between physical network infrastructure and the virtualized switch environment. Understanding the isolation mechanisms at the Distributed Port Group level ensures that this default wide-range trunking does not compromise virtual machine security or data integrity.
Symptoms:
VMware vCenter Server 8.0.x
VMware vSphere ESXi 8.0.x
vSphere Distributed Switch (vDS)
This configuration is by-design. The Uplink Port Group serves as a transparent 802.1Q trunk pipe between the physical switch and the vDS. Security enforcement occurs at the individual Distributed Port Group level, not the Uplink level.
The default configuration is technically secure and does not constitute a security risk based on these architectural principles:
For further details on vDS architecture, see .