# Missing information about overlay network using rancher

**URL:** <https://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021>\
**Category:** Rancher 1.x\
**Created:** [December 27, 2016, 1:07pm UTC](https://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021 "2016-12-27T13:07:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![marhyno](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@marhyno](https://forums.suse.com/u/marhyno)\
**Post date:** [December 27, 2016, 1:07pm UTC](https://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021/1 "2016-12-27T13:07:25Z")

</div>

Hello everyone,

I am new to rancher community and hopefully I will find answer here because one thing gets me really confused. When we talk about overlay networking using rancher and we have 2 or more cloud providers (e.g. AWS, Azure, RackSpace) and we connect them using Rancher which runs on server in our premises. How the containers will be connected. Every cloud provider will be connected to our premises and also between them ? So if we set command on AWS container to send something to Azure container - will the traffic go through our premises or directly there is a tunnel between those two.

So in the end - 3 providers + 1 Rancher means = 6 = Like full mesh ? Or only 3 connections.

Thank you very much and sorry if this is such a basic question but nobody has answered my question yet and I asked many times.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [December 27, 2016, 3:47pm UTC](https://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021/2 "2016-12-27T15:47:20Z")

</div>

An IPSec container runs on each host and creates (up to) a full mesh of direct host-to-host tunnels as needed. So a request to a container (C2) on another host (H2) goes:

`C1 -> IPSec-on-H1 ---ipsec-tunnel--> IPSec-on-H2 -> C2`

Container communication does not involve the rancher/server container.

Asked many times where?

---

<div class="post-metadata">

**Author:** ![marhyno](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@marhyno](https://forums.suse.com/u/marhyno)\
**Post date:** [December 28, 2016, 11:24pm UTC](https://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021/3 "2016-12-28T23:24:04Z")

</div>

Hi Vincent, thank you very very much for your answer 🙂 .  
I asked this question many times not here, but directly to engineers who have already deployed rancher in their environment and offered it to customers. But nobody seemed to care for my question.

So again, thanks for explanation, it really helped me 🙂

---

<div class="post-metadata">

**Author:** ![leodotcloud](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/leodotcloud/32/3103_2.png) [@leodotcloud](https://forums.suse.com/u/leodotcloud)\
**Post date:** [January 3, 2017, 8:39pm UTC](https://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021/4 "2017-01-03T20:39:46Z")

</div>

This is an old post: [http://rancher.com/day-life-packet-inside-rancher](http://rancher.com/day-life-packet-inside-rancher)  
Some of the stuff mentioned in this post is obsolete but the core networking stuff is similar in the newer releases.
