1.5

Table Of Contents
d Select an internal port.
e Select a protocol for the type of traffic to forward.
f Click OK.
6 Click OK.
Add an IP Translation Rule to an Organization Network
An organization administrator can configure certain organization networks to provide IP translation by adding
a NAT mapping rule.
When you add a new IP translation rule to an organization network, it appears at the bottom of the NAT
mapping rule list. For information about how to set the order in which NAT mapping rules are enforced, see
“Reorder NAT Mapping Rules for an Organization Network,” on page 27.
When you create an IP translation rule for a network, vCloud Director adds a DNAT and SNAT rule to the
vShield Edge associated with the network's port group. The DNAT rule translates an external IP address to an
internal IP address for inbound traffic. The SNAT rule translates an internal IP address to an external IP address
for outbound traffic. If the network is also using IP masquerade, the SNAT rule takes precedence.
Only system administrators can assign external IP addresses to a network. Contact your system administrator
if your organization network does not have external IP addresses.
Prerequisites
A routed organization network and an external IP address.
Procedure
1 Click Administration.
2 Select Cloud Resources > Networks.
3 Right-click the organization network name and select Configure Services.
4 Click the NAT Mapping tab and click Add.
5 Select IP Translation and configure the rule.
a Select an external IP address.
b Type the IP address of the destination virtual machine.
n
If the virtual machine is fenced, type its external IP address.
n
If the virtual machine is not fenced, type its IP address.
c Click OK.
6 Click OK.
Reorder NAT Mapping Rules for an Organization Network
NAT mapping rules are enforced in the order in which they appear in the NAT mapping list. An organization
administrator can change the order of the rules in the list.
When you add a new NAT mapping rule (IP translation or port forwarding) to an organization network, it
appears at the bottom of the NAT mapping rule list. To enforce the new rule before an existing rule, reorder
the rules.
Prerequisites
A routed organization network with two or more NAT mapping rules.
Chapter 3 Managing Cloud Resources
VMware, Inc. 27