Powering on identical virtual machines which are included in different vApps might result in a conflict. To allow powering on of identical virtual machines in different vApps without conflicts, you must fence the vApp.

Fencing a vApp isolates the MAC and IP addresses of the virtual machines and changes the connection type of the organization VDC networks from direct to fenced. On the fenced networks firewall is automatically enabled and configured so that only outgoing traffic is allowed. When you fence a vApp, you can also configure NAT and firewall rules on the fenced networks.


  • You can fence only direct vApp networks. If the vApp uses more than one network and the other networks are, for example, routed, only the direct network is fenced.
  • The virtual machines in the vApp that use the direct network must be stopped, so that the direct vApp network is not currently in use.


  1. On the Virtual Datacenters dashboard screen, click the card of the virtual data center you want to explore, and select vApps from the left panel.
  2. Click Card Icon to view the vApps in a card view.
  3. In the card of the selected vApp, click Details.
  4. Click the Networks tab.
  5. If the vApp is not fenced, click the Edit button.
  6. Toggle on the Fence vApp option and click OK.


The IP and MAC addresses of the virtual machines become isolated. You can power on identical virtual machines in different vApps without a conflict.