VLAN creation Windows 10 enterprise and professional

Windows 10 finally introduces builtin VLAN tagging; replacing the Intel Advanced Network Services or the similar functions of the Broadcom Advanced Control Suite.

Still found to be working as of Anniversary Update in Windows 10 professional and enterprise.

Also, tagging untrusted networks to the edge, such as user’s “Internet” VLAN, can help protect baseboard management stacks from attack such as:

To set this up, we needed to install hyper-v within the builtin turn windows features on or off, to get the vSwitch functions, done even if we don't intend running any guests.

The hyper-v GUI only offers the ability to setup one management interface, suggest leaving this one detagged, but you can then use powershell to go and create the other tagged interfaces that we wanted, these show up as vEthernet in the network interfaces GUI.

Importantly, specify -ManagementOS on the extra interfaces, then these appear in the Control Panel for configuring with IP addresses or other use.

  1. Create virtual nics as needed: Add-VMNetworkAdapter
  2. Set which 802.1q tags they have Set-VMNetworkAdapterVlan

Example

I like all host vlan to use the host's own mac address. Find it with Get-NetAdapter -Physical | select macaddress and replace AC-DE-48-23-45-67 with that value.