# Routing Managed Network

**URL:** <https://forums.suse.com/t/routing-managed-network/2252>\
**Category:** Rancher 1.x\
**Created:** [March 31, 2016, 6:23pm UTC](https://forums.suse.com/t/routing-managed-network/2252 "2016-03-31T18:23:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bengerman](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/bengerman/32/1127_2.png) [@bengerman](https://forums.suse.com/u/bengerman)\
**Post date:** [March 31, 2016, 6:23pm UTC](https://forums.suse.com/t/routing-managed-network/2252/1 "2016-03-31T18:23:53Z")

</div>

I found that I am able to communicate directly with containers on the managed network simply by adding any one of the hosts as a gateway to the network `ip route add 10.42.0.0/16 via <my rancher node>`  
Is this a supported feature/use case? Or is this something that happens to work that may be removed/broken in the future?  
(obviously if I continue to use it, I’d do it by advertising the route, not manually adding it)

It looks like maybe this would break in a multi-environment setup:

> Under Rancher’s network, a container will be assigned both a Docker bridge IP (172.17.0.0/16) and a Rancher managed IP (10.42.0.0/16) on the default docker0 bridge. Containers within the same environment are then routable and reachable via the managed network.

Can someone confirm?

---

<div class="post-metadata">

**Author:** ![Eduardo\_Terzella](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/eduardo_terzella/32/6268_2.png) [@Eduardo\_Terzella](https://forums.suse.com/u/Eduardo_Terzella)\
**Post date:** [April 5, 2016, 11:06pm UTC](https://forums.suse.com/t/routing-managed-network/2252/2 "2016-04-05T23:06:58Z")

</div>

Hello,

I have the same doubts.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [April 6, 2016, 3:33am UTC](https://forums.suse.com/t/routing-managed-network/2252/3 "2016-04-06T03:33:00Z")

</div>

This is a bug, not a feature, and will be fixed. The host should only route traffic that is coming from local containers.

The “supported” way would be with a container that’s job is to explicitly route, or something like the OpenVPN catalog templates that already exist.

---

<div class="post-metadata">

**Author:** ![leodotcloud](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/leodotcloud/32/3103_2.png) [@leodotcloud](https://forums.suse.com/u/leodotcloud)\
**Post date:** [October 20, 2016, 1:38am UTC](https://forums.suse.com/t/routing-managed-network/2252/4 "2016-10-20T01:38:48Z")

</div>

@bengerman  
I am looking at [https://github.com/rancher/rancher/issues/4324](https://github.com/rancher/rancher/issues/4324)

I tried to reproduce this issue but have not been successful. I have hosts on AWS, added route as you mentioned but I am not able to ping. Could you please share your steps to reproduce this issue?

---

<div class="post-metadata">

**Author:** ![leodotcloud](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/leodotcloud/32/3103_2.png) [@leodotcloud](https://forums.suse.com/u/leodotcloud)\
**Post date:** [October 20, 2016, 2:11am UTC](https://forums.suse.com/t/routing-managed-network/2252/5 "2016-10-20T02:11:52Z")

</div>

Ok, I have been able to reproduce it locally on my laptop using Virtual Machines.

---

<div class="post-metadata">

**Author:** ![chshawkn](https://avatars.discourse-cdn.com/v4/letter/c/839c29/32.png) [@chshawkn](https://forums.suse.com/u/chshawkn)\
**Post date:** [July 5, 2017, 10:01am UTC](https://forums.suse.com/t/routing-managed-network/2252/6 "2017-07-05T10:01:19Z")

</div>

@vincent Although this is a bug, but I do need a convenient way like this to access containers in managed network.  
I think we should not simply add a iptables rule to ban this.  
We need a config option to enable/disable communicate with managed network.

I have multi rancher hosts, after execute `ip route add 10.42.0.0/16 via <rancher node x>`, I can only access containers on rancher node x, cant access containers on rancher node y, z … I found the vxlan container did not forward packets to other hosts.

I want to access any container in managed network via any rancher host.  
How can I achieve this? Please help!

---

<div class="post-metadata">

**Author:** ![chshawkn](https://avatars.discourse-cdn.com/v4/letter/c/839c29/32.png) [@chshawkn](https://forums.suse.com/u/chshawkn)\
**Post date:** [July 5, 2017, 3:09pm UTC](https://forums.suse.com/t/routing-managed-network/2252/7 "2017-07-05T15:09:48Z")

</div>

I found the answer myself. Execute `iptables -t nat -A POSTROUTING -j MASQUERADE` on vxlan container.
