# Restricting Network between services/containers

**URL:** <https://forums.suse.com/t/restricting-network-between-services-containers/1867>\
**Category:** Rancher 1.x\
**Created:** [February 26, 2016, 3:52pm UTC](https://forums.suse.com/t/restricting-network-between-services-containers/1867 "2016-02-26T15:52:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fbrbovic](https://avatars.discourse-cdn.com/v4/letter/f/7ea924/32.png) [@fbrbovic](https://forums.suse.com/u/fbrbovic)\
**Post date:** [February 26, 2016, 3:52pm UTC](https://forums.suse.com/t/restricting-network-between-services-containers/1867/1 "2016-02-26T15:52:22Z")

</div>

Is there an easy way to restrict network access between services/containers which are not linked together but still use rancher managed network ? currently all of the containers can talk to each other which is not that secure for our use case.

I know I can mess around with IPTables on each host , but that’s not going to work well, when new services and containers are dropped and added and new IP’s assigned. Is there a way to manage it all automatically?

Thanks

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [February 26, 2016, 6:30pm UTC](https://forums.suse.com/t/restricting-network-between-services-containers/1867/2 "2016-02-26T18:30:07Z")

</div>

There is not an automated way to do this now, but I basically agree: [https://github.com/rancher/rancher/issues/2817#issuecomment-172047720](https://github.com/rancher/rancher/issues/2817#issuecomment-172047720)

It should be possible to dynamically read the links from metadata and syncs that up with IPTables rules. Then you could run that as a global service (“run one container on each host”).

---

<div class="post-metadata">

**Author:** ![fbrbovic](https://avatars.discourse-cdn.com/v4/letter/f/7ea924/32.png) [@fbrbovic](https://forums.suse.com/u/fbrbovic)\
**Post date:** [February 26, 2016, 7:51pm UTC](https://forums.suse.com/t/restricting-network-between-services-containers/1867/3 "2016-02-26T19:51:38Z")

</div>

Yes something like that would be perfect. Any plans to make something like that part of Rancher anytime soon?

---

<div class="post-metadata">

**Author:** ![yunspace](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/yunspace/32/304_2.png) [@yunspace](https://forums.suse.com/u/yunspace)\
**Post date:** [August 10, 2016, 11:19pm UTC](https://forums.suse.com/t/restricting-network-between-services-containers/1867/4 "2016-08-10T23:19:46Z")

</div>

I’m quite interested in this feature also. FYI There is a new issue raised that relate to this [https://github.com/rancher/rancher/issues/3895](https://github.com/rancher/rancher/issues/3895)
