Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

Changes to IP Masquerade and Firewall Rules in vCloud Director 5.1 (2036040)

Details

In vCloud Director 1.x, you could configure an external NAT-routed organization network to provide IP masquerade services. When you enabled IP masquerade, vCloud Director translated a virtual machine's private, internal IP address to a public IP address for outbound traffic, effectively hiding the internal IP address of the virtual machine from the external network. This setting was enabled by default and added a NAT rule that allowed all virtual machines on the organization network to communicate with the external network.

For vCloud Director 5.1, the networking infrastructure was updated and the IP Masquerade setting was removed.

In addition, in vCD 1.x, external NAT-routed organization networks had a default firewall rule that would allow all outgoing traffic. In vCD 5.1, there are no default firewall rules.

Solution

To create the equivalent of the IP Masquerade behavior in vCD 5.1, a system administrator must create an Edge Gateway and sub-allocate IP pools for use by its gateway services. By default, Edge Gateways do not have any NAT rules, so a system or organization administrator must add an SNAT rule to the gateway, applied on the external network interface of the gateway, where the original IP address is either the range or CIDR of the organization VDC network, and the translated IP is one of the IPs from the sub-allocation range.

To create the equivalent of vCD 1.x's default firewall rule, a system administrator must create an Edge Gateway and thenĀ  a system or organization administrator should add a firewall rule that allows all outgoing traffic. Specifically, they should add a firewall rule where Source is internal, Destination is external, protocol is ANY, and action is Allow.

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 0 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 0 Ratings
Actions
KB: