Configuring Trunking in Virtual Environments
If you are deploying a sensor using a hypervisor and plan to monitor multiple VLAN through a trunk port, special configuration is needed.
Configure your physical switch port and Genian ZTNA as described in Installing Network Sensor.
Special settings will be configured within the virtual network to allow Genian ZTNA to communicate with the physical trunk port.
For all hypervisors, ensure the NIC assigned to Genian ZTNA supports VLANs and is placed in
promiscuous mode.The virtual sensor host must be linked to the physical switch using a virtual switch.
ESXi
Different configurations are possible depending on which switching technology is being used in ESXi.
vSwitch
On the Virtual Switch, edit the port group:
Enable
VGT ModeSet the VLAN ID to
4095.This will allow traffic from all VLANs to travel through the virtual switch, between your Physical switch port and Genian ZTNA.
Distributed vSwitch
Under Home > Inventory > Networking, Edit Settings for the desired dvPortGroup.
Go to Policies > VLAN:
Set VLAN type to VLAN
TrunkingSet range or list of VLANs.
This will allow traffic from all specified VLANs to travel through the virtual switch, between all virtual machines and physical NICs assigned to the vSwitch.
Hyper-V
Warning
Hyper-V does not support trunk configuration in the GUI, Powershell is required.
Please be warned trunking configurations will not be visible in the GUI after they have been configured.
Because Hyper V names all interfaces "Network Adapter" by default, we strongly advise renaming, removing + recreating, or using a script to select target interface by MAC address.In the example below, we will demonstrate deleting a single interface and recreating it, before configuring trunking.
These changes will result in temporary disconnection, and are best performed with the guest system is powered down.
In Powershell, enter the following commands with the bracketed values changed to match your environment:
List the interfaces connected to the VM:
Get-VMNetworkAdaptervlan -VMName [vmname]Delete the existing interfaces that were output by the above command. Repeat as needed.
Remove-VMNetworkAdapter -VMName [vmname] -Name "[Network Adapter]"Add back interfaces using the command below. Assign unique interface names if adding multiple interfaces. (Single interface recommended)
Add-VMNetworkadapter -VMName [vmname] -Name "[Eth0]"Lastly, configure the interface(s) as a trunk port. Include the native VLAN in the allowed VLAN list (
-AllowedVlanIdList).
Set-VMNetworkAdapterVlan -VMName [vmname] -VMNetworkAdapterName "[Eth0]" -Trunk -AllowedVlanIdList "[native vlan],[other vlans]" -NativeVlanId [native vlan]Check your interfaces
Get-VMNetworkAdaptervlan -VMName [vmname]
Important
In trunk mode, Hyper-V passes traffic for every VLAN in
-AllowedVlanIdList to the VM tagged, except the -NativeVlanId,
which is passed untagged. The native VLAN must still be listed in
-AllowedVlanIdList. If it is left out, untagged traffic on the native
VLAN can be dropped and the sensor may lose its network connection.
# Native VLAN 1 is untagged, VLANs 10, 20 and 30 are tagged
Set-VMNetworkAdapterVlan -VMName [vmname] -VMNetworkAdapterName "Eth0" -Trunk -AllowedVlanIdList "1,10,20,30" -NativeVlanId 1
# Native VLAN 100 is untagged, VLANs 101-200 are tagged
Set-VMNetworkAdapterVlan -VMName [vmname] -VMNetworkAdapterName "Eth0" -Trunk -AllowedVlanIdList "100-200" -NativeVlanId 100
# Incorrect: the native VLAN (1) is missing from the allowed list
Set-VMNetworkAdapterVlan -VMName [vmname] -VMNetworkAdapterName "Eth0" -Trunk -AllowedVlanIdList "10,20,30" -NativeVlanId 1
Real world syntax examples:
Get-VMNetworkAdaptervlan -VMName GenianZTNARemove-VMNetworkAdapter -VMName GenianZTNA -Name "Network Adapter"Add-VMNetworkadapter -VMName GenianZTNA -Name "Eth0"Set-VMNetworkAdapterVlan -VMName GenianZTNA -VMNetworkAdapterName "Eth0" -Trunk -AllowedVlanIdList "1,10,20,30" -NativeVlanId 1Get-VMNetworkAdaptervlan -VMName GenianZTNA
Citrix Hypervisor (Xenserver)
In the host Network Tab in Xencenter:
Add an
external networkfor each VLAN, and assign each entry to the NIC that is connected to the switch trunk port.