# Private network without IPSec overlay

**URL:** <https://forums.suse.com/t/private-network-without-ipsec-overlay/1941>\
**Category:** Rancher 1.x\
**Created:** [March 4, 2016, 5:56pm UTC](https://forums.suse.com/t/private-network-without-ipsec-overlay/1941 "2016-03-04T17:56:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hwinkel](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/hwinkel/32/951_2.png) [@hwinkel](https://forums.suse.com/u/hwinkel)\
**Post date:** [March 4, 2016, 5:56pm UTC](https://forums.suse.com/t/private-network-without-ipsec-overlay/1941/1 "2016-03-04T17:56:01Z")

</div>

We like all the concepts in rancher to deploy services in a total cloud centric way. However in a more traditional IT department the IPsec Overlay may causes some trouble here.

Is there a way to mange service/container with rancher based on a fixed network topology which the security team already has splitted in different zones (VLANS) which are all routable but have given security rules between them.

I would model this with different labels attached to hosts in a given department (VLAN) and only allow service to be deployed there. We also like to use the internal DNS discovery goodies ranher provides. But is there a way to avoid the additional IPSec tunnels and use the preexisting routed connectivity?

an intersting article about the network stuff in container networks is here at k8s:

> **[Why Kubernetes doesn’t use libnetwork](http://blog.kubernetes.io/2016/01/why-Kubernetes-doesnt-use-libnetwork.html)**
>
> The official Kubernetes blog.

  
With the arrival of k8s at rancher now it would be interesting to hear about the direction of  
rancher in terms of networking CNI etc.

---

<div class="post-metadata">

**Author:** ![kaos](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/kaos/32/38_2.png) [@kaos](https://forums.suse.com/u/kaos)\
**Post date:** [April 27, 2017, 8:18am UTC](https://forums.suse.com/t/private-network-without-ipsec-overlay/1941/2 "2017-04-27T08:18:24Z")

</div>

Ping @denise et al. Do you have any reply to this?

We’re in a similar situation, where we want to have agent nodes in the same environment, but where we don’t want rancher to setup the IPSec network, due to the nodes being in different silos. We can provide a custom IPSec network for rancher to use, that we manage for this setup, though. So the question is, could it work, and is there anything special we need to do in rancher to make this work.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [April 27, 2017, 9:22am UTC](https://forums.suse.com/t/private-network-without-ipsec-overlay/1941/3 "2017-04-27T09:22:48Z")

</div>

We support the existing IPSec and vxlan. Integrating other CNI implementations is possible but we have no immediate plans to implement more that I’m aware of.

---

<div class="post-metadata">

**Author:** ![kaos](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/kaos/32/38_2.png) [@kaos](https://forums.suse.com/u/kaos)\
**Post date:** [April 27, 2017, 2:17pm UTC](https://forums.suse.com/t/private-network-without-ipsec-overlay/1941/4 "2017-04-27T14:17:08Z")

</div>

Thanks for the reply vincent.
