You can configure certain vApp networks to provide port forwarding by adding a NAT mapping rule.

Port forwarding provides external access to services running on virtual machines on the vApp network.

When you configure port forwarding, VMware Cloud Director maps an external port to a service that runs on a virtual machine dedicated to inbound traffic.

When you add a port forwarding rule to a vApp network, it appears at the bottom of the NAT mapping rule list. For information about how to set the order in which port forwarding rules are enforced, see


  • Verify that the vApp network is routed.
  • Verify that the firewall on the vApp network is activated. If you deactivate the firewall, the NAT mapping rules are no longer applied to the vApp network.


  1. On the Virtual Data Center dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select vApps.
  2. Click Card Icon to view the vApps in a card view.
  3. In the card of the selected vApp, click Details.
  4. On the Networks tab, click a network to view the network details.
  5. Click Services and click Edit.
  6. To enable NAT, toggle on the NAT option.
  7. From the NAT Type drop-down menu, select Port Forwarding, and click Add.
  8. (Optional) To enable IP masquerading, select the check box.
  9. Configure the port-forwarding rule.
    1. Select an external port.
    2. Select a port to which to forward.
    3. Select a virtual machine interface.
    4. Select a protocol for the type of traffic to forward.
  10. Click Save.

What to do next

If necessary, rearrange the port-forwarding rules by using the Move Up or Move Down buttons.