nerdexam
Cisco

300-715 · Question #267

An engineer must configure an HTTP probe on a Cisco ISE virtual appliance running on VMWare using a dedicated interface for profiling. The interface is assigned to the VM Network port group. The…

The correct answer is C. Set Promiscuous mode to Accept in the Port Group properties. To allow a Cisco ISE VM's profiling interface to receive SPAN traffic on VMware, promiscuous mode must be explicitly set to 'Accept' at the port group level.

Architecture and Deployment

Question

An engineer must configure an HTTP probe on a Cisco ISE virtual appliance running on VMWare using a dedicated interface for profiling. The interface is assigned to the VM Network port group. The engineer is logged into the hypervisor with a user account that only provides access to the Cisco ISE VM and the network settings for the VM. Which security setting must be changed for this interface to accept SPAN traffic?

Options

  • ASet Promiscuous mode to inherit from vSwitch in the Port Group properties.
  • BSet Promiscuous mode to inherit from Port Group in the vSwitch properties.
  • CSet Promiscuous mode to Accept in the Port Group properties.
  • DSet Promiscuous mode to Accept in the vSwitch properties.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    79% (23)
  • D
    14% (4)

Why each option

To allow a Cisco ISE VM's profiling interface to receive SPAN traffic on VMware, promiscuous mode must be explicitly set to 'Accept' at the port group level.

ASet Promiscuous mode to inherit from vSwitch in the Port Group properties.

Inheriting from the vSwitch might not result in 'Accept' if the vSwitch itself is set to reject, and it's not the most direct configuration for a specific VM interface.

BSet Promiscuous mode to inherit from Port Group in the vSwitch properties.

Promiscuous mode is configured at the vSwitch or Port Group level, not inherited from the Port Group in vSwitch properties.

CSet Promiscuous mode to Accept in the Port Group properties.Correct

Setting Promiscuous mode to 'Accept' in the Port Group properties allows the virtual machine's network adapter within that port group to receive all traffic traversing the virtual switch ports to which the port group is connected, including SPAN traffic for profiling. This is a common requirement for network monitoring applications like Cisco ISE's profiling probes when using SPAN/RSPAN.

DSet Promiscuous mode to Accept in the vSwitch properties.

While setting promiscuous mode at the vSwitch level to 'Accept' would allow it for all port groups and VMs on that switch, the question specifies modifying this interface and the engineer's access is limited to the VM and its network settings, making port group configuration more appropriate and granular.

Concept tested: VMware promiscuous mode for SPAN traffic

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-8F0E4E76-E547-497D-81AE-511B41258679.html

Topics

#VMware Networking#Promiscuous Mode#Cisco ISE Profiling#SPAN

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice