5.1

Table Of Contents
4 Click the Firewall tab.
5 Drag the firewall rules to establish the order in which the rules are applied.
6 Click OK.
Enable VPN for an Edge Gateway
You can enable VPN for organization vDCs backed by an edge gateway and create a secure tunnel from one
of those organization vDC networks to another network.
vCloud Director supports VPN between organization vDC networks backed by edge gateways and both
organization vDC networks in the same organization and remote networks.
System administrators and organization administrators can enable VPN.
Procedure
1 Click the Manage & Monitor tab and click Organization vDCs in the left pane.
2 Double-click the organization vDC name to open the organization vDC.
3 Click the Edge Gateways tab, right-click the edge gateway name and select Edge Gateway Services.
4 Click the VPN tab and select Enable VPN.
5 (Optional) Click Configure Public IPs, type a public IP address, and click OK.
6 Click OK.
What to do next
Create a VPN tunnel between an organization vDC network backed by the edge gateway to another network.
Configure Public IPs for External Networks
You can configure a public IP address for external networks associated with an edge gateway.
Procedure
1 Click the Manage & Monitor tab and click Organization vDCs in the left pane.
2 Double-click the organization vDC name to open the organization vDC.
3 Click the Edge Gateways tab, right-click the edge gateway name and select Edge Gateway Services.
4 Click the VPN tab and click Configure Public IPs.
5 Type an IP address to act as the public IP address for each external network and click OK.
Creating VPN Tunnels on an Edge Gateway
You can create VPN tunnels between organization vDC networks on the same organization, between
organization vDC networks on different organizations, and between an organization vDC network and an
external network.
vCloud Director does not support multiple VPN tunnels between the same two edge gateways. If there is an
existing tunnel between two gateways and you want to add another subnet to the tunnel, delete the existing
VPN tunnel and create a new one that includes the new subnet.
Create a VPN Tunnel In an Organization for an Organization vDC Network Backed by an Edge Gateway
You can create a VPN tunnel between an organization vDC network that is backed by edge gateway and
another organization vDC in the same organization.
System administrators and organization administrators can create VPN tunnels.
Chapter 5 Managing Cloud Resources
VMware, Inc. 71