Skip to content

Virtual Switches

Hyper-V virtual switches are critical for managing network connectivity between virtual machines (VMs) and physical networks. They act as a bridge between VMs and the underlying hardware, enabling features like VLAN tagging, port mirroring, and network segmentation. This section explains how to create and configure virtual switches in Hyper-V, including VLAN tagging and port mirroring.


Creating Virtual Switches

Hyper-V supports three types of virtual switches: External, Internal, and Private. Each serves different networking scenarios.

1. External Switch

Connects VMs to the physical network, allowing them to communicate with external devices.
Steps:
- Using Hyper-V Manager:
1. Open Hyper-V Manager.
2. Select the host, then click Virtual Switch Manager.
3. Choose External and select a physical network adapter.
4. Assign the switch a name and click OK.

  • Using PowerShell:
    New-VMSwitch -Name "ExternalSwitch" -SwitchType External -NetAdapterName "Ethernet"
    

2. Internal Switch

Allows VMs on the same host to communicate with each other and the host, but not external networks.
Steps:
- PowerShell:

New-VMSwitch -Name "InternalSwitch" -SwitchType Internal

3. Private Switch

Restricts VMs to communicate only with each other.
Steps:
- PowerShell:

New-VMSwitch -Name "PrivateSwitch" -SwitchType Private


Configuring VLAN Tagging

VLAN tagging segments traffic across physical networks. Assign VLAN IDs to virtual switches or VM network adapters.

1. Assign VLAN ID to a Virtual Switch

  • PowerShell:
    Set-VMSwitch -Name "ExternalSwitch" -VlanId 10
    
    This applies VLAN 10 to all VMs connected to the switch.

2. Assign VLAN ID to a VM’s Virtual NIC

  • PowerShell:
    Set-VMNetworkAdapter -VMName "VM01" -VlanId 20
    
    This tags traffic from VM01 with VLAN 20.

Note: Ensure VLAN IDs are within the range 1–4094 and match the physical switch configuration.


Configuring Port Mirroring

Port mirroring (also calledSPAN) replicates traffic from a source port to a destination port for monitoring.

1. Enable Port Mirroring via PowerShell

Set-VMSwitch -Name "ExternalSwitch" -PortMirroring "VM01-VirtualNic, MonitoringVM-VirtualNic"
- Replace VM01-VirtualNic with the source VM’s network adapter name.
- Replace MonitoringVM-VirtualNic with the destination VM’s network adapter name.

2. Verify Port Mirroring

Get-VMSwitchPort -Name "ExternalSwitch" | Select-Object VMName, VlanId, PortMirroring

Troubleshooting Tips

  • Network Connectivity Issues:
  • Verify the switch type matches your requirements (e.g., External for external access).
  • Check VLAN configurations on both the virtual switch and VM network adapters.

  • Port Mirroring Failures:

  • Ensure the destination VM’s network adapter is configured for mirroring.
  • Confirm the physical switch supports VLAN tagging and port mirroring.

  • PowerShell Errors:

  • Use Get-Help New-VMSwitch or Get-Help Set-VMSwitch for parameter details.

Key takeaways

  • Choose the right switch type: External for external access, Internal for host/VM communication, Private for isolated VMs.
  • VLAN tagging segments traffic; apply VLAN IDs at the switch or VM network adapter level.
  • Port mirroring enables network monitoring; configure source and destination ports via PowerShell or the Hyper-V UI.
  • Always validate VLAN IDs and switch configurations to avoid connectivity issues.