5.1

Table Of Contents
Table 6-2. Types of Organization vDC Networks and Their Requirements
Organization vDC
Network Connection Description Requirements
Direct connection to an
external network.
Provides direct layer 2 connectivity to machines and
networks outside of the organization vDC. Machines
outside of this organization vDC can connect directly to
machines within the organization vDC.
The cloud must contain an
external network.
Routed connection to an
external network.
Provides controlled access to machines and networks
outside of the organization vDC via an Edge Gateway.
System administrators and organization administrators
can configure network address translation (NAT) and
firewall settings on the gateway to make specific virtual
machines in the vDC accessible from an external
network.
The vDC must contain an Edge
Gateway and a network pool.
No connection to an
external network.
Provides an isolated, private network that machines in
the organization vDC can connect to. This network
provides no incoming or outgoing connectivity to
machines outside this organization vDC.
The vDC must contain a network
pool.
By default, only virtual machines in the organization vDC that contains the network can use it. When you
create an organization vDC network, you can specify that it is shared. A shared organization vDC network
can be used by all virtual machines in the organization.
Edge Gateways
An Edge Gateway provides a routed connection between an organization vDC network and an external
network. It can provide any of the following services, defined in the GatewayFeatures element of the Edge
Gateway's Configuration.
FirewallService
Specifies firewall rules that, when matched, block or allow incoming or
outgoing network traffic. See “Firewall Service Configurations,” on page 158.
GatewayDhcpService
Provides DHCP services to virtual machines on the network. A variant of this
service, DhcpService, is intended to provide DHCP services in vApp networks.
See “Gateway DHCP Service Configurations,” on page 166.
GatewayIpsecVpnService
Defines one or more virtual private networks that connect an Edge Gateway
to another network in or outside of the cloud.
LoadBalancerService
Distributes incoming requests across a set of servers. See “Load Balancer
Service Configurations,” on page 163.
NatService
Provides network address translation services to computers on the network.
StaticRoutingService
Specifies static routes to other networks. See “Static Routing Service
Configurations,” on page 161.
For an example of adding services to an Edge Gateway, see “Configure Edge Gateway Services,” on
page 156. For more information about any of these services, see the vShield Administration Guide.
External Networks and Network Pools
External networks and network pools are vSphere resources backed by vSphere portgroup, VLAN, or
DVswitch objects. A system administrator must create them, as described in “Create an External Network,”
on page 219 and “Create a Network Pool,” on page 222. You must supply a reference to an external network
when you create an Edge Gateway. When you create an organization vDC, you must supply a reference to a
network pool if the vDC is to be able to contain routed or isolated networks. See “Retrieve a List of External
Networks and Network Pools,” on page 204
vCloud API Programming Guide
150 VMware, Inc.