You can configure certain vApp networks to provide an IP translation by adding a NAT mapping rule.

When you create an IP translation rule for a network, vCloud Director adds a DNAT and SNAT rule to the edge gateway associated with the network's port group. The DNAT rule translates an external IP address to an internal IP address for inbound traffic. The SNAT rule translates an internal IP address to an external IP address for outbound traffic.


  • Verify that the vApp network is routed.
  • Verify that the firewall on the vApp network is activated. If you deactivate the firewall, the NAT mapping rules are no longer applied to the vApp network.


  1. On the Virtual Data Center dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select vApps.
  2. Click Card Icon to view the vApps in a card view.
  3. In the card of the selected vApp, click Details.
  4. On the Networks tab, click a network to view the network details.
  5. Click Services and click Edit.
  6. To enable NAT, toggle on the NAT option.
  7. From the NAT Type drop-down menu, select IP Translation and click Add.
  8. Select a virtual machine interface and click Keep.
  9. Select a mapping mode.
  10. If you selected Manual mapping mode, enter an external IP address.
  11. Click Save.

What to do next

If necessary, rearrange the IP translation rules by using the Move Up or Move Down buttons.