# Connection between Rancher hosts

**URL:** <https://forums.suse.com/t/connection-between-rancher-hosts/5976>\
**Category:** General\
**Created:** [March 27, 2017, 7:13am UTC](https://forums.suse.com/t/connection-between-rancher-hosts/5976 "2017-03-27T07:13:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moshe\_Nadler](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/moshe_nadler/32/2176_2.png) [@Moshe\_Nadler](https://forums.suse.com/u/Moshe_Nadler)\
**Post date:** [March 27, 2017, 7:13am UTC](https://forums.suse.com/t/connection-between-rancher-hosts/5976/1 "2017-03-27T07:13:15Z")

</div>

Hi,

I just want to make sure that all the traffic that flows between the rancher hosts is encrypted and goes via the IPsec tunnel as default or are there any exception cases?

Moreover, what are the ports that I need to open between the Rancher server and the hosts?

Thanks!

Moshe

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 27, 2017, 7:18am UTC](https://forums.suse.com/t/connection-between-rancher-hosts/5976/2 "2017-03-27T07:18:08Z")

</div>

IPSec is for container-to-container traffic. agent-to-server is via the host registration URL. If you want it to be TLS you need to run a balancer or proxy that does TLS-termination and set the registration URL to `https`.

---

<div class="post-metadata">

**Author:** ![Moshe\_Nadler](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/moshe_nadler/32/2176_2.png) [@Moshe\_Nadler](https://forums.suse.com/u/Moshe_Nadler)\
**Post date:** [March 27, 2017, 8:27am UTC](https://forums.suse.com/t/connection-between-rancher-hosts/5976/3 "2017-03-27T08:27:53Z")

</div>

> [@vincent](#):
>
> IPSec is for container-to-container traffic

Thanks,  
There also a very good explanation on this thread:

> [@Information on ports to be opened between Master Server and Hosts](http://forums.suse.com/t/information-on-ports-to-be-opened-between-master-server-and-hosts/5936):
>
> I am trying to setup Rancher in AWS as below. Rancher Master Server Security Group Rules: Inbound 8080 (0.0.0.0/0) - For Agent communication Outbound - 80, 443 Rancher Hosts Security Group Rules: Inbound - 22 ( ssh login from a particular host) Outbound - 80, 443 and 8080 I am adding the hosts as ‘Custom Hosts’ i.e. installing the Rancher Agent on the host machine manually. The hosts has been installed with Docker already. The agent is getting installed successfully hosts and it also sho…
