Skip to content

Port Settings

Managing MAC Address Spoofing, Wake-on-LAN, and QoS for Virtual Switch Ports

MAC Address Spoofing Prevention & Detection

MAC address spoofing can be mitigated by enforcing strict validation rules and implementing monitoring mechanisms. Enable MAC address validation to ensure only authorized MAC addresses are allowed on a port:
- PowerShell:

Set-VMNetworkAdapter -VMName "VMName" -MacAddress "00-11-22-33-44-55" -Confirm:$false  
This command explicitly sets a static MAC address for the VM’s network adapter, preventing spoofing. For dynamic validation, configure the virtual switch to reject unauthorized MAC addresses via the hypervisor’s management console (e.g., Hyper-V Manager).

Detection & Logging:
- Use network monitoring tools like Wireshark, Microsoft Network Monitor, or hypervisor-specific audit logs to detect spoofing attempts.
- Enable logging on the virtual switch to capture unauthorized MAC address changes. For Hyper-V, use Get-VMNetworkAdapter to review MAC address assignments and verify consistency.
- Regularly audit MAC address assignments and ensure virtual switches are configured to alert on spoofing attempts via centralized logging systems (e.g., Splunk, ELK Stack).

Wake-on-LAN (WoL) Configuration

Wake-on-LAN allows VMs to be remotely powered on via network signals. Configure WoL parameters for virtual machine network adapters:
- PowerShell:

Set-VMNetworkAdapter -VMName "VMName" -WakeOnLanEnabled $true  
This enables WoL for the VM. Ensure the physical NIC supports WoL and the BIOS/UEFI settings allow wake-on-network activity.

Additional Parameters:
- Set the WoL MAC address specifically for WoL functionality:

Set-VMNetworkAdapter -VMName "VMName" -MacAddress "00-11-22-33-44-55"  
This ensures the virtual switch forwards WoL packets using the specified MAC address. Configure the virtual switch to forward WoL packets to the physical network.

Note: These PowerShell commands are Hyper-V specific. For VMware vSphere, use esxcli network vswitch standard portgroup set with appropriate parameters.

Quality of Service (QoS) Settings

QoS settings prioritize traffic on the virtual switch, ensuring critical VMs receive adequate bandwidth. This is particularly useful in environments with mixed workloads.

Configuration

  • PowerShell:
    Set bandwidth limits and priorities for a VM’s network adapter:
    Set-VMNetworkAdapter -VMName "VMName" -MinimumBandwidthRate 100Mbps -MaximumBandwidthRate 1000Mbps  
    
    Adjust the -MinimumBandwidthRate and -MaximumBandwidthRate parameters to define bandwidth constraints.

To prioritize traffic using 802.1p tags:

Set-VMNetworkAdapter -VMName "VMName" -Priority 1  
Priorities range from 0 (highest) to 7 (lowest). Ensure the virtual switch is configured to pass 802.1p tags to the physical network (e.g., via hypervisor settings or switch port configuration).

Note: QoS requires the underlying physical switch to support traffic prioritization (e.g., 802.1p tags). Verify that the virtual switch is configured to propagate these tags to the physical network. For Hyper-V, enable 802.1p tagging via the virtual switch manager. For VMware, use distributed virtual switches (DVS) with QoS policies.