1.5

Table Of Contents
Procedure
1 Click Administration.
2 Select Cloud Resources > Networks.
3 Right-click the organization network name and select Configure Services.
4 Click the NAT Mapping tab.
5 Click and drag the rules to establish the order in which the rules are applied.
6 Click OK.
Enable Site-to-Site VPN for an Organization Network
An organization administrator can enable site-to-site VPN for an organization network and then create a secure
tunnel to another network.
vCloud Director supports site-to-site VPN between organization networks in the same organization,
organization networks in different organizations (including organization networks in different instances of
vCloud Director), and remote networks.
Prerequisites
n
A routed organization network.
n
vShield Manager 5.0.
Procedure
1 Click Administration.
2 Select Cloud Resources > Networks.
3 Right-click the organization network name and select Configure Services.
4 Click the Site-to-Site VPN tab and select Enable site-to-site VPN.
5 (Optional) Type a public IP address.
If the external network to which the organization network is routed is behind a NAT device, you must
provide a publicly accessible IP address that faces the Internet.
6 Click OK.
What to do next
Create a VPN tunnel to another network.
Create a VPN Tunnel Within an Organization
An organization administrator can create a VPN tunnel between two organizations networks in the same
organization.
If the tunnel endpoints have a firewall between them, you must configure it to allow the following IP protocols
and UDP ports:
n
IP Protocol ID 50 (ESP)
n
IP Protocol ID 51 (AH)
n
UDP Port 500 (IKE)
n
UDP Port 4500
vCloud Director User's Guide
28 VMware, Inc.