If the edge gateway for your vCloud Director organization virtual data center has been converted to an advanced edge gateway, you can use the vCloud Director tenant portal to work with that edge gateway NAT rules. You can create a source NAT (SNAT) rule to change the source IP address from a public to private IP address or the reverse. You can create a destination NAT (DNAT) rule to change the destination IP address from a public to private IP address or the reverse.
When creating NAT rules, you can specify the original and translated IP addresses by using the following formats:
- IP address; for example, 192.0.2.0
- IP address range; for example, 192.0.2.0-192.0.2.24
- IP address/subnet mask; for example, 192.0.2.0/24
When you configure a SNAT or a DNAT rule on an edge gateway in the vCloud Director environment, you always configure the rule from the perspective of your organization virtual data center. A SNAT rule translates the source IP address of packets sent from an organization virtual data center network out to an external network or to another organization virtual data center network. A DNAT rule translates the IP address, and optionally the port, of packets received by an organization virtual data center network that are coming from an external network or from another organization virtual data center network.
The public IP addresses must have been added to the edge gateway interface on which you want to add the rule. For DNAT rules, the original (public) IP address must have been added to the edge gateway interface and for SNAT rules, the translated (public) IP address must have been added to the interface.
To use the vCloud Director tenant portal to work with edge gateway services, the edge gateway must be converted to an advanced edge gateway. You can do this on the edge gateway in the vCloud Director Web console or from the tenant portal. For details on performing this step from the tenant portal, see Convert an Edge Gateway to an Advanced Edge Gateway.
- Open Edge Gateway Services.
- Navigate to Networking > Edges.
- Select the edge gateway to edit, and click Configure Services.
- Click the NAT to view the NAT Rules screen.
- Depending on which type of NAT rule you are creating, click DNAT Rule or SNAT Rule.
- Configure a Destination NAT rule (outside coming inside).
Option Description Applied On Select the interface on which to apply the rule. Original IP/Range
Type the required IP address.
This address must be the public IP address of the edge gateway for which you are configuring the DNAT rule. In the packet being inspected, this IP address or range would be those that appear as the destination IP address of the packet. These packet destination addresses are the ones translated by this DNAT rule.
Protocol Select the protocol to which the rule applies. To apply this rule on all protocols, select Any. Original Port (Optional) Select the port or port range that the incoming traffic uses on the edge gateway to connect to the internal network on which the virtual machines are connected. This selection is not available when the Protocol is set to ICMP or Any. ICMP Type When you select ICMP (an error reporting and a diagnostic utility used between devices to communicate error information) for Protocol, select the ICMP Type from the drop-down menu.
ICMP messages are identified by the type field. By default, the ICMP type is set to any.
Translated IP/Range Type the IP address or a range of IP addresses to which destination addresses on inbound packets will be translated.
These addresses are the IP addresses of the one or more virtual machines for which you are configuring DNAT so that they can receive traffic from the external network.
Translated Port (Optional) Select the port or port range that inbound traffic is connecting to on the virtual machines on the internal network. These ports are the ones into which the DNAT rule is translating for the packets inbound to the virtual machines. Description (Optional) Type a description that helps identify what this rule is doing. Enabled Toggle on to enable this rule. Enable logging Toggle on to have the address translation performed by this rule logged.
- Configure a Source NAT rule (inside going outside).
Option Description Applied On Select the interface on which to apply the rule. Original Source IP/Range Type the original IP address or range of IP addresses to apply to this rule.
These addresses are the IP addresses of one or more virtual machines for which you are configuring the SNAT rule so that they can send traffic to the external network.
Translated Source IP/Range Type the required IP address.
This address is always the public IP address of the gateway for which you are configuring the SNAT rule. Specifies the IP address to which source addresses (the virtual machines) on outbound packets are translated to when they send traffic to the external network.
Description (Optional) Type a description that helps identify what this rule is doing. Enabled Toggle on to enable this rule. Enable logging Toggle on to have the address translation performed by this rule logged.
- Click Keep to add the rule to the on-screen table.
- Repeat the steps to configure additional rules.
- Click Save changes to save the rules to the system.
What to do next
Add corresponding edge gateway firewall rules for the SNAT or DNAT rules you just configured. See Add an Edge Gateway Firewall Rule Using the Tenant Portal.