VMware Cloud Community
vSohill
Expert
Expert
Jump to solution

Static route vs Nating

Hi,

If I have vApp routed network Should I use Nating or Static route in order to reach the external world.

f the client want to reach their vCops can they reach it through VPN or Nating Am I right ?

Can you please give an example how can I utilize the Sataic routing ?

Thank you community

0 Kudos
1 Solution

Accepted Solutions
Sreec
VMware Employee
VMware Employee
Jump to solution

Firstly you need to understand that routed vapp means there is already a routing in place.There are multiple scenarios were you might need a routing for a vapp network, for eg you have a vapp network connected to routed org vdc network -A, You have one more vapp network connected to another org vdc network B . If there is a requirement for ORG VDC A need to communicate with ORG VDC B , you can configure Routes at Edge level of Org VDC A&B ,not just static routing,dynamic routing is also supported if you are using NSX Edges.

With regards to public network access, you can simply NAT private IP of the VCD VM with Public IP which would be usually part of sub allocation pool of NSX/VCNS Edge device,that way the rule will be x.x.x.x(private) Translates to Y.Y.Y.Y(Public) with respective port numbers  and firewall rules for ingress/outgress traffic. Choice is yours whether you need separate Public for each Private IP or it can be 1:Many NAT as well. Routing and NAT will not secure your network,rather it will establish network connectivity. This is were VPN will benefit ,so in that case all your Internal Networks in VCD will be able to communicate with Internal Networks in your organisation or may be a different site altogether via Public network and establish a secure IP Sec tunnel.  KB is very well documented for IPSEC -->Configuring IPsec VPN within VMware vCloud Air to a remote network (2051370) | VMware KB  . Let me know if you have any further queries Smiley Happy

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered

View solution in original post

0 Kudos
6 Replies
Sreec
VMware Employee
VMware Employee
Jump to solution

Firstly you need to understand that routed vapp means there is already a routing in place.There are multiple scenarios were you might need a routing for a vapp network, for eg you have a vapp network connected to routed org vdc network -A, You have one more vapp network connected to another org vdc network B . If there is a requirement for ORG VDC A need to communicate with ORG VDC B , you can configure Routes at Edge level of Org VDC A&B ,not just static routing,dynamic routing is also supported if you are using NSX Edges.

With regards to public network access, you can simply NAT private IP of the VCD VM with Public IP which would be usually part of sub allocation pool of NSX/VCNS Edge device,that way the rule will be x.x.x.x(private) Translates to Y.Y.Y.Y(Public) with respective port numbers  and firewall rules for ingress/outgress traffic. Choice is yours whether you need separate Public for each Private IP or it can be 1:Many NAT as well. Routing and NAT will not secure your network,rather it will establish network connectivity. This is were VPN will benefit ,so in that case all your Internal Networks in VCD will be able to communicate with Internal Networks in your organisation or may be a different site altogether via Public network and establish a secure IP Sec tunnel.  KB is very well documented for IPSEC -->Configuring IPsec VPN within VMware vCloud Air to a remote network (2051370) | VMware KB  . Let me know if you have any further queries Smiley Happy

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
0 Kudos
vSohill
Expert
Expert
Jump to solution

Thanks again Sreec ,

Routing in place what is mean ?

0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

VM's are connected to a Router(That is why i mentioned there is already a routing in place,because it is a direct connect network to a router, which is nothing but VAPP Router(Not Org VDC level) and from there you can connect all the way to Org- Network which can be direct or again a Routed Org Network.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
vSohill
Expert
Expert
Jump to solution

Thank you very much Sreec

I have an external network backed by PG on my vDS, SNAT works fine. Can I configure SNAT in other Network that backed to other PG? Kindly can write example with IPs ?

0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

For sure you can write SNAT/DNAT rules . Hope you are asking for example with IP ? 

Lets say your VM's are on network 172.16.10.0/24 connected to Org-VDC Routed network,all the way to external network via vSphere PG

> Select the respective Edge interface - it would be external interface in our case

> Type would be SNAT

>Orginal Ip/Range - 172.16.10.0/24 ( In our case we are configuring SNAT for entire subnet)

>Port - for eg :22

>Translated IP - 172.16.20.1

>Port -for eg :22

>Protocol - TCP

>Finally enable the rule

You will need a firewall rule also to allow the respective traffic.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
vSohill
Expert
Expert
Jump to solution

Perfect, Many thansk.

I will come back to you if I have a question regarding DNAT .

Thanks again

0 Kudos