Troubleshooting VLAN Misconfiguration on vSphere Distributed Switch — Trunk vs Access Port
Exhibit
vsish -e get /net/portsets/DvsPortset-0/ports/200/status Port 200 Status: Link up: yes Speed (Mbps): 10000 Duplex: full MTU: 1500 Packets received: 1024 Packets transmitted: 2048 Errors: 0 Drops: 0 vsish -e get /net/portsets/DvsPortset-0/ports/200/filter Filtering: Allowed MAC addresses: (none) Allowed VLANs: 100, 200, 300 Blocked VLANs: (none) net-stats -l | grep "DvsPortset-0:200" DvsPortset-0:200 TX packets:2048 RX packets:1024 TX errors:0 RX errors:0 TX drops:0 RX drops:0
Refer to the exhibit. An administrator checks the status of a distributed switch port and sees no errors or drops. However, virtual machines on this port cannot communicate with the default gateway at 192.168.200.1. What is the most likely cause?
Quick Answer
The port being configured as a trunk with Allowed VLANs 100, 200, and 300 when the VM expects a plain access port on VLAN 200 is the most likely cause because a trunk port and an access port serve fundamentally different roles, and connecting an endpoint that only understands untagged traffic on one VLAN to a port carrying multiple tagged VLANs breaks the assumption the VM's network stack is built on. A trunk port is designed for devices that can interpret 802.1Q tags themselves and sort traffic by VLAN ID. A typical VM, by contrast, expects to receive plain untagged traffic belonging to a single VLAN, which is what an access port configuration on VLAN 200 alone would provide. Because the port here allows three VLANs instead of being pinned to just VLAN 200, the VM either does not receive properly tagged traffic it can parse, or its traffic gets mixed with unrelated VLANs, and reaching the gateway fails even though the physical port itself shows no errors or drops, since the problem is a configuration mismatch, not a hardware or link issue. When a distributed switch port shows a healthy link but a VM cannot reach its gateway, and the port config lists multiple allowed VLANs, check whether that port should actually be a single-VLAN access-style configuration instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The port is configured with Allowed VLANs 100, 200, 300, which is a trunk configuration, but the virtual machine expects an access port on VLAN 200.
The exhibit shows the port has Allowed VLANs: 100, 200, 300. This is unusual because a port should typically be assigned to a single VLAN (access port) or carry multiple VLANs (trunk port). If the port is set to allow multiple VLANs but the virtual machine expects a specific VLAN, packets may be misconfigured. However, the most likely cause is that the port is configured as a trunk port (allows multiple VLANs) when it should be an access port for VLAN 200. This can cause the virtual machine to receive traffic from other VLANs or not tag its own traffic correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The port has no allowed MAC addresses, which may cause filtering.
Why it's wrong here
No MAC filtering is configured; it's not blocking traffic.
- ✓
The port is configured with Allowed VLANs 100, 200, 300, which is a trunk configuration, but the virtual machine expects an access port on VLAN 200.
Why this is correct
The port should be set to VLAN 200 only (access) instead of allowing multiple VLANs. This misconfiguration leads to connectivity issues.
- ✗
The MTU is set to 1500, which is standard and should work fine.
Why it's wrong here
MTU 1500 is standard and not causing the issue.
- ✗
The link speed is 10 Gbps, which is sufficient.
Why it's wrong here
Speed is not the problem.
Visual reference
Go deeper
Related to this question
About these practice questions
This VCP-DCV question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on VCP-DCV
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator configures a distributed switch with a single uplink on each host and a port group with VLAN 10. After connecting a VM to the port group, the VM cannot communicate with other VMs on the same VLAN but on different hosts. What is a likely cause?
medium- ✓ A.The physical switch port is set to access mode with VLAN 10.
- B.The distributed switch has no teaming configured.
- C.The physical switch port connected to the uplink is set to trunk mode and is tagging the VLAN.
- D.The VLAN ID is not set correctly on the VM's virtual network adapter.
Why A: When the physical switch port is in access mode with VLAN 10, it expects untagged frames. However, the distributed port group with VLAN 10 tags the frames with VLAN 10. This mismatch causes the physical switch to drop or mishandle the traffic, preventing the VM from communicating with other VMs on the same VLAN across hosts. Option B is incorrect because teaming is not required for basic connectivity; a single uplink suffices. Option C describes trunk mode which would actually accept tagged frames, so it would work. Option D is incorrect because the VLAN ID is configured on the port group, not on the VM's virtual adapter.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.