The Forged Transmits option setting affects traffic transmitted from a virtual machine. When the Forged transmits option is set to Accept, ESXi does not compare source and effective MAC addresses. The switch drops any outbound frame from a virtual machine adapter with a source MAC address that is different from the one in the .vmx configuration file. If the "Forged Transmits" policy is set to accept, this is a finding. The Forged transmits option is applicable for traffic that is transmitted from the virtual machine to the virtual switch. There are valid use cases to set forged transmits to accept, like nested ESXi. By forged I mean a MAC address that is not supplied by Vcenter, like you would need for a bond interface. It is generally recommended to use vSphere vSwitch security policy "Forged Transmits" to reject unauthorized MAC addresses. To protect against MAC impersonation, you can set the Forged transmits option to reject. MAC address changes and forged transmits: Every virtual machine has two MAC addresses by definition. Forged transmits also looks at the MAC addresses of your virtual machines, however is operating on outgoing traffic. When the Forged transmit option is set to Reject, the switch does not perform filtering, and permits all outbound frames. Configure any virtual switch attached to the VM-Series firewall to allow the following modes: promiscuous mode, MAC address changes, and Forged transmits. From the vSphere Web Client go to Configure >> Networking >> Virtual Switches. Right-click Networking in the VMware Host Client inventory and click Add port group from the pop-up menu. Look at ESXi 5.1 and BPDU Guard for full article with all details about this topic.