# IPSec vs VXLan Networks

**URL:** <https://forums.suse.com/t/ipsec-vs-vxlan-networks/6706>\
**Category:** Rancher 1.x\
**Created:** [June 23, 2017, 12:16am UTC](https://forums.suse.com/t/ipsec-vs-vxlan-networks/6706 "2017-06-23T00:16:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nthomson](https://avatars.discourse-cdn.com/v4/letter/n/3d9bf3/32.png) [@nthomson](https://forums.suse.com/u/nthomson)\
**Post date:** [June 23, 2017, 12:16am UTC](https://forums.suse.com/t/ipsec-vs-vxlan-networks/6706/1 "2017-06-23T00:16:18Z")

</div>

Apologies if this is a stupid question, but I haven’t found it addressed anywhere:

What are the trade-offs of using IPSec versus the VXLan managed network implementations? So far all I’ve been able to glean from various GitHub issues is that VXLan performs faster but loses the inherent encryption between hosts.

---

<div class="post-metadata">

**Author:** ![egnoriega](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@egnoriega](https://forums.suse.com/u/egnoriega)\
**Post date:** [June 28, 2017, 10:43pm UTC](https://forums.suse.com/t/ipsec-vs-vxlan-networks/6706/2 "2017-06-28T22:43:39Z")

</div>

VXLan allows you to set up networks programmatically at a low cost, and does support encryption as an option to the overlay driver. (Look up the `--opt encrypted` argument to `network create`. )

IPSec is a protocol for protecting traffic in terms of detecting changes and/or encrypting the data payload, and works in either a direct or tunneled mode. It does not require encryption, and can be used without the data

At the end of the day they are really two different technologies targeting different use cases.

---

<div class="post-metadata">

**Author:** ![cas0559](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/cas0559/32/3036_2.png) [@cas0559](https://forums.suse.com/u/cas0559)\
**Post date:** [July 27, 2017, 1:58am UTC](https://forums.suse.com/t/ipsec-vs-vxlan-networks/6706/3 "2017-07-27T01:58:37Z")

</div>

Could you elaborate on the differing use cases? Ours is that we are on a shared network so we want RANCHER to provide encrypted comms for all our intracontainer environment. Thanks

---

<div class="post-metadata">

**Author:** ![nthomson](https://avatars.discourse-cdn.com/v4/letter/n/3d9bf3/32.png) [@nthomson](https://forums.suse.com/u/nthomson)\
**Post date:** [July 31, 2017, 7:52pm UTC](https://forums.suse.com/t/ipsec-vs-vxlan-networks/6706/4 "2017-07-31T19:52:38Z")

</div>

I’d have to agree. I get that the first reply is technically correct, but in Rancher it appears I’m given two distinct options: VXLan or IPSec. If I have two things to choose from I need some background regarding why there are two options and in what cases I should use each one.
