# Clarification on firewall rules?

**URL:** <https://forums.suse.com/t/clarification-on-firewall-rules/4388>\
**Category:** Rancher 1.x\
**Created:** [October 21, 2016, 10:51pm UTC](https://forums.suse.com/t/clarification-on-firewall-rules/4388 "2016-10-21T22:51:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [October 21, 2016, 10:51pm UTC](https://forums.suse.com/t/clarification-on-firewall-rules/4388/1 "2016-10-21T22:51:46Z")

</div>

Hello Everyone,

I’m setting up a Rancher Server cluster, with multiple management nodes for HA, and multiple nodes to host the containers.

[Installing Rancher Server (Multi Nodes) : Requirements](http://docs.rancher.com/rancher/v1.1/en/installing-rancher/installing-server/multi-nodes/#requirements) says the following about the Firewall rules:

> - Ports that need to be opened on Nodes
> - Global Access: TCP Ports 22 , 80, 443, 18080 (Optional: Used to view the management stack as it comes up)
> - Access between nodes:
> - UDP Ports 500, 4500
> - TCP Ports: 2181, 2376, 2888, 3888,6379

When the docs say “Access between nodes”, do I need to manually add access rules for the 172.16.0.0/12 and 10.42.x.x networks? Or do Docker and Rancher do that automatically?

I’m adding these rules for to allow acccess from our routable, production networks; but do I need to add rules for the overlay networks also?

Thank you,

-= Stefan

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [October 22, 2016, 12:08am UTC](https://forums.suse.com/t/clarification-on-firewall-rules/4388/2 "2016-10-22T00:08:25Z")

</div>

No, 172.16 is the local docker network and doesn’t leave that host, and 10.42 is the overlay network sent over IPSec so the physical network doesn’t ever see packets with those IPs.

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [October 22, 2016, 1:04am UTC](https://forums.suse.com/t/clarification-on-firewall-rules/4388/3 "2016-10-22T01:04:15Z")

</div>

> so the physical network doesn’t ever see packets with those IPs

I see. But iptables itself does see the packets, which might part of our problem.

However, it sounds like Docker and Rancher both add their own rules to iptables, but add them to their own chains, and maybe only to the nat table? I don’t neeed to manually manage these rules.

But I do need to ensure that other tools, like Puppet or Ansible, don’t run in and remove the rules.

-= Stefan
