When SpoofGuard is configured, if the IP address of a virtual machine changes, traffic from the virtual machine may be blocked until the corresponding configured port/segment address bindings are updated with the new IP address.

Enable SpoofGuard for the port group(s) containing the guests. When enabled for each network adapter, SpoofGuard inspects packets for the prescribed MAC and its corresponding IP address.


  1. From your browser, log in with admin privileges to an NSX Manager at https://<nsx-manager-ip-address>.
  2. Select Networking > Segments > Segment Profiles.
  3. Click Add Segment Profile and select Spoof Guard.
  4. Enter a name.
  5. To enable port level SpoofGuard, set Port Bindings to Enabled.
  6. Click Save.