# Ensuring Cross-Host Communication

**URL:** <https://forums.suse.com/t/ensuring-cross-host-communication/8257>\
**Category:** Rancher 1.x\
**Created:** [January 21, 2018, 2:18am UTC](https://forums.suse.com/t/ensuring-cross-host-communication/8257 "2018-01-21T02:18:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stryter](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@stryter](https://forums.suse.com/u/stryter)\
**Post date:** [January 21, 2018, 2:18am UTC](https://forums.suse.com/t/ensuring-cross-host-communication/8257/1 "2018-01-21T02:18:07Z")

</div>

I am having a problem establishing cross-host communication on my rancher set up.

I have two physical hosts running RancherOS and on the first host I have Rancher server running.  
The problem I am encountering is the healthcheck container on host #2 is stuck in an ‘initializing’ state. I have read in a few places that this indicates there is a problem communicating between hosts. I followed the steps in the Toubleshooting section to try pinging the healthcheck container running host #1 from the healthcheck container on host #2 and I found that I could not reach the other container.

At this point, my suspicion is that it could be a firewall issue but I am not sure where to look or what to try next. **Are there any specific ports that need to be open on a router to allow cross-host communication?**

For clarity, both these hosts are plugged into a physical hardware firewall router.

Thanks!

---

<div class="post-metadata">

**Author:** ![superseb](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/superseb/32/2424_2.png) [@superseb](https://forums.suse.com/u/superseb)\
**Post date:** [January 24, 2018, 3:16pm UTC](https://forums.suse.com/t/ensuring-cross-host-communication/8257/2 "2018-01-24T15:16:30Z")

</div>

The ports needed are described here: [http://rancher.com/docs/rancher/v1.6/en/hosts/custom/#security-groupsfirewalls](http://rancher.com/docs/rancher/v1.6/en/hosts/custom/#security-groupsfirewalls)

For ipsec (default overlay network) it’s UDP/500 and UDP/4500 between all the IPs that are shown in the `Infrastructure` -\> `Hosts` view.
