When SpoofGuard is configured, if the IP address of a virtual machine changes, traffic from the virtual machine may be blocked until the corresponding configured port/segment address bindings are updated with the new IP address.

Enable SpoofGuard for the port group(s) containing the guests. When enabled for each network adapter, SpoofGuard inspects packets for the prescribed MAC and its corresponding IP address.


  1. With admin privileges, log in to NSX Manager.
  2. Select Networking > Segments > Segment Profiles.
  3. Click Add Segment Profile and select Spoof Guard.
  4. Enter a name.
  5. To enable port level SpoofGuard, set Port Bindings to Enabled.
  6. Click Save.