A vSphere administrator is troubleshooting connectivity issues for a virtual machine on a standard switch. The VM is configured with VLAN 100, but cannot ping the default gateway. The VMkernel port on the host is on VLAN 200. The physical switch port connected to the host is configured as a trunk port allowing VLANs 100 and 200. Which action should the administrator take to resolve the issue?
Trap 1: Enable promiscuous mode on the VM port group.
Promiscuous mode lets a vNIC receive frames not addressed to it; it does not correct a VLAN tagging mismatch between the VM's port group and the uplink. It is tempting because it is often reached for when traffic appears blocked; it would be correct for monitoring or nested-virtualisation capture scenarios.
Trap 2: Change the physical switch port to access mode on VLAN 100.
Access mode carries only one VLAN, so the trunk would stop passing VLAN 200 for the VMkernel port, breaking host management traffic. It is tempting because access ports simplify VLAN assignment; it would be correct if the host needed only a single VLAN on that uplink.
Trap 3: Set the VM port group VLAN to 4095.
VLAN 4095 on a port group trunks every VLAN, so the guest's own VLAN 100 tagging would be passed untagged or double-tagged incorrectly, and the gateway remains unreachable. It is tempting because 4095 resembles a trunk-all setting; it would be correct for a port group carrying multiple VLANs to a VLAN-aware guest.
- A
Enable promiscuous mode on the VM port group.
Why it fails: Promiscuous mode lets a vNIC receive frames not addressed to it; it does not correct a VLAN tagging mismatch between the VM's port group and the uplink. It is tempting because it is often reached for when traffic appears blocked; it would be correct for monitoring or nested-virtualisation capture scenarios.
- B
Change the physical switch port to access mode on VLAN 100.
Why it fails: Access mode carries only one VLAN, so the trunk would stop passing VLAN 200 for the VMkernel port, breaking host management traffic. It is tempting because access ports simplify VLAN assignment; it would be correct if the host needed only a single VLAN on that uplink.
- C
Ensure the VM port group is set to VLAN 100.
The VM's port group must carry VLAN 100 to match the VM's tagging; if the port group is set to VLAN 200 or none, traffic is tagged or untagged incorrectly and cannot reach the gateway. The physical trunk already permits VLAN 100, so only the port group setting needs correcting.
- D
Set the VM port group VLAN to 4095.
Why it fails: VLAN 4095 on a port group trunks every VLAN, so the guest's own VLAN 100 tagging would be passed untagged or double-tagged incorrectly, and the gateway remains unreachable. It is tempting because 4095 resembles a trunk-all setting; it would be correct for a port group carrying multiple VLANs to a VLAN-aware guest.