1.5

Table Of Contents
5 Type a range of IP addresses or use the default range.
vCloud Director uses these addresses to satisfy DHCP requests. The range of DHCP IP addresses cannot
overlap with the static IP pool for the organization network.
6 Set the default lease time and maximum lease time or use the default values.
7 Click OK.
vCloud Director updates the network to provide DHCP services.
Enable the Firewall for an Organization Network
An organization administrator can configure certain organization networks to provide firewall services. Enable
the firewall on an organization network to enforce firewall rules on incoming traffic, outgoing traffic, or both.
When you enable the firewall, you can specify a default firewall action to deny all incoming and outgoing
traffic or to allow all incoming and outgoing traffic. You can also add specific firewall rules to allow or deny
traffic that matches the rules to pass through the firewall. These rules take precedence over the default firewall
action. See “Add a Firewall Rule to an Organization Network,” on page 24.
If a system administrator specified syslog server settings and those settings have been applied to the
organization network, then you can log events related to the default firewall action. For information about
applying syslog server settings, see “Apply Syslog Server Settings to an Organization Network,” on
page 35. To view the current syslog server settings see “View Syslog Server Settings for an Organization
Network,” on page 35.
Prerequisites
A routed organization network.
Procedure
1 Click Administration.
2 Select Cloud Resources > Networks.
3 Right-click the organization network name and select Configure Services.
4 Click the Firewall tab and select Enable firewall.
5 Select the default firewall action.
6 (Optional) Select the Log check box to log events related to the default firewall action.
7 Click OK.
Add a Firewall Rule to an Organization Network
An organization administrator can add firewall rules to an organization network that supports a firewall. You
can create rules to allow or deny traffic that matches the rules to pass through the firewall.
For a firewall rule to be enforced, you must enable the firewall for the organization network. See “Enable the
Firewall for an Organization Network,” on page 24.
When you add a new firewall rule to an organization network, it appears at the bottom of the firewall rule list.
For information about how to set the order in which firewall rules are enforced, see “Reorder Firewall Rules
for an Organization Network,” on page 25.
If a system administrator specified syslog server settings and those settings have been applied to the
organization network, then you can log firewall rule events. For information about applying syslog server
settings, see “Apply Syslog Server Settings to an Organization Network,” on page 35. To view the current
syslog server settings see “View Syslog Server Settings for an Organization Network,” on page 35.
vCloud Director User's Guide
24 VMware, Inc.