5.1

Table Of Contents
Enable VPN for an Organization vDC Network
You can enable VPN for an organization vDC network and create a secure tunnel to another network.
vCloud Director supports VPN between organization vDC networks in the same organization, organization
vDC networks in different organizations (including organization vDC networks in different instances of
vCloud Director), and remote networks.
System administrators and organization administrators can enable VPN.
Prerequisites
n
An external routed organization vDC network.
n
vShield Manager 5.1.
Procedure
1 Click the Manage & Monitor tab and click Organization vDCs in the left pane.
2 Double-click the organization vDC name to open the organization vDC.
3 Click the Org vDC Networks tab, right-click the organization vDC network name, and select Configure
Services.
4 Click the VPN tab and select Enable VPN.
5 (Optional) Type a public IP address.
6 Click OK.
What to do next
Create a VPN tunnel to another network.
Create a VPN Tunnel Within an Organization
You can create a VPN tunnel between two organization vDC networks in the same organization.
Both system administrators and organization administrators can create VPN tunnels.
If a firewall is between the tunnel endpoints, you must configure it to allow the following IP protocols and
UDP ports:
n
IP Protocol ID 50 (ESP)
n
IP Protocol ID 51 (AH)
n
UDP Port 500 (IKE)
n
UDP Port 4500
Prerequisites
n
At least two routed organization vDC networks with non-overlapping IP subnets and VPN enabled on
both networks.
n
vShield Manager 5.1.
Procedure
1 Click the Manage & Monitor tab and click Organization vDCs in the left pane.
2 Double-click the organization vDC name to open the organization vDC.
3 Click the Org vDC Networks tab, right-click the organization vDC network name, and select Configure
Services.
Chapter 5 Managing Cloud Resources
VMware, Inc. 87