Networking Guide

Network Security and Secure Access 3
vCloud Air provides features and functionality to ensure network security and secure access to your
resources in the cloud.
This chapter includes the following topics:
n
“About Network Security,” on page 27
n
“About Firewall Rules,” on page 28
n
“Add a Firewall Rule,” on page 29
n
“VPN and Remote Networks,” on page 30
n
“About IPsec VPN,” on page 31
n
“About Setting up an IPsec VPN Connection,” on page 31
n
“Set up an IPsec VPN Connection to a Remote Site,” on page 32
n
“SSL VPN for Data Center Extension,” on page 34
About Network Security
Your subscription and configuration decisions within vCloud Air have network security implications.
The following table illustrates the security differences between the service offerings—Dedicated Cloud
versus Virtual Private Cloud. Choose the service offering that meets your security needs.
Table 31. Security Differences Between Service Offerings
Dedicated Cloud Virtual Private Cloud
RESOURCES
n
Physically separated hosts
n
Logically separated network and storage
n
Shared cloud
n
Logically separated network, compute, and storage
SEGMENTATION
n
Segmented virtual data centers based on organizations
n
Because of segmentation, not subject to multi-tenancy
n
No virtual data center segmentation
SECURITY BENEFITS
n
Ideal for running regulated applications
n
Ideal for shared access within a single organization
The type of networks you add to vCloud Air and how you connect your virtual machines to those networks
have security considerations as well. Connect your virtual machines to the appropriate networks based on
their security needs.
VMware, Inc.
27