How to Configure LAN Segment in VMware Workstation

Quick Insight

You configure a LAN Segment in VMware Workstation to build a private VLAN for select guests. First, open the settings of the first VM and pick LAN Segment under the network adapter. Then, click the button to add a new segment and give it a name. Next, set the second VM to join that same segment. This traps all traffic inside the group with no DHCP server. As a result, you test isolated network apps or routing roles with full control.

In this guide, you’ll learn how to set up LAN Segment settings. We’ll show each step for virtual machines in VMware Workstation.

VMware Segment Connection

Configuring LAN Segment in VMware Workstation

In previous guides, we set up Bridged, Host-Only, NAT, and Custom Specific Virtual Network settings. Next, we’ll look at this feature in VMware Pro. Also, we’ll see what it does.

What is this feature in VMware? It’s a private group for virtual machines. With it, VMs don’t get IP addresses from a local DHCP server.

When you use this virtual setup, the VM gets an IP via APIPA. APIPA stands for Automatic Private Internet Protocol Addressing. So the machine gets an address from the 169.254.0.0/16 block.

VMware Workstation 8 and earlier versions called this structure Team. However, new versions renamed it.

In this setup, all VMs get IPs from the 169.254.0.0/16 block. Additionally, they never get IP addresses from a DHCP server.

For more information on APIPA, you can read this Microsoft article.

Creating a Private VLAN in VMware and Adding VMs to the Same Group

Set up two virtual machines in VMware Workstation as Client1 and Client2. Then add both VMs to the same group. Follow these steps in order.

Step 1

To add VMs to the same group, create a new Segment. Open the Client1 virtual machine. Then click the Network Adapter option. In Virtual Machine Settings, check the LAN Segment option.

Configuring Virtual Machine Adapter Settings

Step 2

After you check it, click the “LAN Segments…” button.

LAN Segments...

Step 3

In the Global Settings window, press the Add button.

Global Segmentation

Step 4

When you click Add, VMware creates the Segment1 group. Then click the Rename button to change the group’s name.

After you rename the new local group to Local, click OK to close the window.

Naming the Segment

Step 5

This time, you can see the Local group in the drop-down menu.

Adding a VM to a Local Group

Step 6

Select Local and click the OK button.

Local Group

Step 7

As the image below shows, Client1 VM now belongs to LAN Segment / Local.

You don’t need to create a new Segment for Client2 VM. Instead, add Client2 VM to the Local group. Just select Local from the adapter settings.

Configuring Virtual Machine Adapter

Adding the Second VM and Testing the Setup

Step 1

After you create this setup in VMware Workstation, run Client1 and Client2 VMs. You can check Client1’s APIPA IP address in the image below.

APIPA

Step 2

The IP address that Client2 VM got looks like this.

APIPA IP Address

Step 3

In this setup, VMs in the same group can talk to each other. Now, ping Client2 from Client1 VM to check the link.

If the ping fails, turn off Windows Firewall.

Pinging Using Command Prompt

Step 4

Similarly, ping Client1 from Client2 VM and test the link.

Pinging with Command Prompt

Step 5

In this setup, VMs can never access the physical LAN. Ping your 192.168.1.0/24 physical LAN from Client1 VM and check the result.

Pinging

Step 6

Similarly, ping your physical LAN from Client2 VM to check connectivity.

Pinging Client2 VM

Assigning Manual IP Addresses to VMs and Testing the Setup

VMs in the same Segment can get IPs on their own via APIPA. However, you can assign manual IP addresses to VMs in the group.

After assigning manual IPs, test the link. Follow these steps in order.

Step 1

To assign a manual IP to Client1 VM, open Network and Sharing Center. Then click the Ethernet adapter. Assign Client1 the IP 192.168.10.10 from the 192.168.10.0/24 range.

Manual IP Address Configuration

Step 2

Similarly, assign Client2 VM an IP from the 192.168.10.0/24 range. Client2’s IP address is 192.168.10.20.

Manual IP Address Configuration

Step 3

After assigning manual IPs, check that the link works, as shown in the image below. Once you finish these steps, you can build more advanced topologies with private groups. This way, you can improve and test your skills.

Pinging a PC on the Same Group

Six Questions About LAN Segment

What’s the difference between this feature and Host-Only? Aren’t both closed to the outside?

They look similar, but the truth is different. In Host-Only, you can talk to your host computer. In this setup, only machines in the same Segment talk to each other.
Think of Host-Only as a setup where your physical computer acts as a door. However, this setup has no door. It’s a fully isolated island.
APIPA IPs are also a big difference. They use the 169.254.x.x range on their own. Host-Only assigns a private range via DHCP.

Why do machines get 169.254.x.x IPs? Is this normal?

Yes, this is completely normal and expected. In fact, it’s the most distinctive feature of this setup.
The 169.254.0.0/16 range is the APIPA block. If no DHCP server exists, Windows assigns itself an IP from this range.
VMware designed this feature on purpose. Therefore, you don’t need any DHCP server. VMs get IPs on their own and talk to each other. Practical, right?

Can I assign manual IPs to VMs? For example, something like 192.168.1.x?

Absolutely yes! If automatic APIPA bothers you, feel free to assign manual IPs. VMware doesn’t interfere with this at all.
For instance, you can give one machine 10.10.10.10 and the other 10.10.10.20. As long as they’re in the same group, they’ll ping each other.
However, don’t forget this key point: these manual IPs only work between VMs. They still can’t access your physical LAN. They stay fully isolated.

Can I access a printer or server on the physical LAN?

No, unfortunately you can’t. This feature provides full isolation on purpose.
VMs only stay within their own Segments. No door opens to the outside. They can’t reach the physical LAN or the Internet.
Therefore, this feature is perfect for security tests and isolated lab setups. But if you need file sharing or printer access, use Bridged or NAT.

What did older versions use instead? What was the Team structure?

Ah, you remind me of the old days! In Workstation 8 and earlier, this feature was called “Team”. Same idea, just a different name.
In the Team structure, you could also group VMs and create isolated setups. The interface was a bit different, but the core was the same.
VMware 9 and later renamed it. Therefore, if you use a new version, forget the word “Team”.

I can’t ping in this setup. Windows Firewall is off, but the problem persists. What should I do?

In this case, we need to dig a bit deeper. First, make sure the adapter on both machines connects to the right Segment.
Then check the IPs with the ‘ipconfig /all’ command. They must be in the same group. For example, if one is 169.254.10.5, the other should be 169.254.10.6.
If it still doesn’t work, restart the virtual machines. Sometimes services can get stuck. As a last resort, remove and re-add the adapter on both machines. This fixes most problems.

Conclusion

In this guide, we covered setup steps for VMs in VMware Workstation/Player. Additionally, you can create more advanced designs with this virtual feature. Thanks for following us!

They'll Thank You for Discovering This Guide!

Ready to do your loved ones a huge favor with just one click? Knowledge grows as it is shared.

Be the first to share your comment