1.5

Table Of Contents
8 Review the tunnel settings and click Connect.
vCloud Director configures both peer network endpoints.
Create a VPN Tunnel to a Remote Network
You can create a VPN tunnel between an organization network and a remote network.
Both system administrators and organization administrators can create VPN tunnels.
If there is a firewall between the tunnel endpoints, you must configure it to allow the following IP protocols
and UDP ports:
n
IP Protocol ID 50 (ESP)
n
IP Protocol ID 51 (AH)
n
UDP Port 500 (IKE)
n
UDP Port 4500
Prerequisites
n
An external NAT-routed organization network and a routed remote network that uses IPSec.
n
vShield Manager 5.0.
Procedure
1
Click the Manage & Monitor tab and click Organization Networks in the left pane.
2 Right-click the organization network name and select Configure Services.
3 Click the Site-to-Site VPN tab and click Add.
4 Type a name and optional description.
5 Select a remote network from the drop-down menu.
6 Type the peer settings.
7 Review the tunnel settings and click OK.
vCloud Director configures the organization peer network endpoint.
What to do next
Manually configure the remote peer network endpoint.
Enable Static Routing for an Organization Network
You can configure certain organization networks to provide static routing services. After you enable static
routing on an organization network, you can add static routes to allow traffic between different vApp networks
routed to the organization network.
Prerequisites
Verify that you have a routed organization network.
Procedure
1 Click the Manage & Monitor tab and click Organization Networks in the left pane.
2 Right-click the organization network name and select Configure Services.
3 On the Static Routing tab, select Enable static routing and click OK.
vCloud Director Administrator's Guide
60 VMware, Inc.