When port mirroring is enabled on a vSphere Distributed Switch (vDS), virtual machines (VMs) on the same port group or ESXi host may experience intermittent or complete network connectivity loss. This article explains the underlying loop prevention mechanism in vDS and provides steps to restore connectivity while maintaining traffic mirroring.
vSphere Distributed Switch (vDS)
ESXi 7.x, 8.x
VMware vCenter Server
By default, the vSphere Distributed Switch designates a destination port for mirroring as a "receive-only" interface to prevent network loops. If "Normal I/O on destination ports" is set to "Disallowed," the vDS kernel drops all inbound and outbound production traffic (including ARP, ICMP, and standard application traffic) for that destination port, causing the VM to lose network connectivity.
To resolve this connectivity loss while retaining the port mirroring session, adjust the configuration to allow production traffic on the destination port, or implement a secondary vNIC for isolation.
Note: If strict traffic isolation is required, consider adding a secondary vNIC to the destination VM:
If the issue persists, review the ESXi logs to confirm the port status. For instructions on how to retrieve these logs, refer to: How to collect diagnostic information for ESXi hosts.
If you require further assistance or need to speak with a Support Engineer, visit Contact Broadcom Support.