# Externally routing the overlay network

**URL:** <https://forums.suse.com/t/externally-routing-the-overlay-network/3851>\
**Category:** Rancher 1.x\
**Created:** [August 30, 2016, 3:30pm UTC](https://forums.suse.com/t/externally-routing-the-overlay-network/3851 "2016-08-30T15:30:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![olds463](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/olds463/32/7318_2.png) [@olds463](https://forums.suse.com/u/olds463)\
**Post date:** [August 30, 2016, 3:30pm UTC](https://forums.suse.com/t/externally-routing-the-overlay-network/3851/1 "2016-08-30T15:30:00Z")

</div>

Howdy,

What are the options for accessing the overlay network that rancher manages? I’ve changed the subnet that rancher uses 10.42.0.0/16 to a private /24 that is route-able within the office environment here and tested. This works.

My question is now, how do I access containers that are now assigned address on that public network? All attempts fail , most likely due to the overlay network. Before, we had an OpenVPN instance listening in a container, but I do not much like that solution as we have multiple nodes and not very redundant / ease to maintain.

Thanks.

---

<div class="post-metadata">

**Author:** ![Upayavira](https://avatars.discourse-cdn.com/v4/letter/u/ba8739/32.png) [@Upayavira](https://forums.suse.com/u/Upayavira)\
**Post date:** [August 30, 2016, 4:27pm UTC](https://forums.suse.com/t/externally-routing-the-overlay-network/3851/2 "2016-08-30T16:27:04Z")

</div>

My take is that the overlay network is intended for communication _between_ nodes, not for communication from the outside. For that, I’d use the host’s IP. That can be accessed from the Rancher metadata API from within the node. Or, if Rancher was set up correctly, by clicking on the ‘ports’ tab for the service.

You set up Docker on a host that is already routable in your network, and the overlay network assists in your Docker hosts communicating, but once a port is exported by the container, that port on the host would be your way to access the service.

From what (little) I understand of the implementation of the overlay network, I’d suspect you’re heading into deep waters if you try to extend it beyond the scope of Rancher managed hosts - Rancher keeps a VPN connection between each node on the network up-to-date so that traffic between hosts can be direct, and encrypted.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [August 30, 2016, 5:30pm UTC](https://forums.suse.com/t/externally-routing-the-overlay-network/3851/3 "2016-08-30T17:30:29Z")

</div>

We are working to support CNI plugins and convert the current managed networking into one. This type of use-case would probably be better suited to a different networking provider plugin that e.g. just directly uses the provided subnet.
