5.5

Table Of Contents
Create a VPN Tunnel In an Organization
An organization administrator can create a VPN tunnel between two organization virtual datacenter
networks in the same organization.
If the tunnel endpoints have a firewall between them, configure the firewall to allow the following IP
protocols and UDP ports:
n
IP Protocol ID 50 (ESP)
n
IP Protocol ID 51 (AH)
n
UDP Port 500 (IKE)
n
UDP Port 4500
Prerequisites
Verify that you have at least two routed organization virtual datacenter networks with nonoverlapping IP
subnets and VPN enabled on both networks.
Procedure
1 Click Administration and select the organization virtual datacenter.
2 Click the Org VDC Networks tab, right-click the organization virtual datacenter network name, and
select Configure Services.
3 Click the VPN tab and click Add.
4 Type a name and optional description.
5 Select a network in this organization from the drop-down menu and select a peer network.
6 Review the tunnel settings and click OK.
vCloud Director configures both peer network endpoints.
Create a VPN Tunnel Between Organizations
An organization administrator can create a VPN tunnel between two organization virtual datacenter
networks in different organizations. The organizations can be part of the same vCloud Director installation
or a different installation.
Prerequisites
Verify that you have a routed organization virtual datacenter network in each of the organizations. The
organization virtual datacenter networks must have IP subnets that do not overlap and a site-to-site VPN
enabled.
If the tunnel endpoints have a firewall between them, you must configure it to allow the following IP
protocols and UDP ports:
n
IP Protocol ID 50 (ESP)
n
IP Protocol ID 51 (AH)
n
UDP Port 500 (IKE)
n
UDP Port 4500
Procedure
1 Click Administration and select the organization virtual datacenter.
2 Click the Org VDC Networks tab, right-click the organization virtual datacenter network name, and
select Configure Services.
Chapter 2 Managing Cloud Resources
VMware, Inc. 23