# Security with remote hosts

**URL:** <https://forums.suse.com/t/security-with-remote-hosts/9538>\
**Category:** Rancher 1.x\
**Created:** [February 18, 2018, 4:13am UTC](https://forums.suse.com/t/security-with-remote-hosts/9538 "2018-02-18T04:13:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kevinhooke](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kevinhooke](https://forums.suse.com/u/kevinhooke)\
**Post date:** [February 18, 2018, 4:13am UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/1 "2018-02-18T04:13:09Z")

</div>

If you add a remote host with a public ip to a locally installed/running Rancher, what security is there or do you need to put in place to protect the remote host running the rancher-agent?

I’ve configured Access Control on my local Rancher install, but is there anyway you can protect the remote host, for example with ssh keys?

Thanks!  
Kevin

---

<div class="post-metadata">

**Author:** ![kevinhooke](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kevinhooke](https://forums.suse.com/u/kevinhooke)\
**Post date:** [February 18, 2018, 6:21am UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/2 "2018-02-18T06:21:12Z")

</div>

I think this post explains what I wanted to know. So between the rancher-server and remote hosts, IPSec VPN tunnels are created automatically?

> [@Missing information about overlay network using rancher](http://forums.suse.com/t/missing-information-about-overlay-network-using-rancher/5021):
>
> Hello everyone, I am new to rancher community and hopefully I will find answer here because one thing gets me really confused. When we talk about overlay networking using rancher and we have 2 or more cloud providers (e.g. AWS, Azure, RackSpace) and we connect them using Rancher which runs on server in our premises. How the containers will be connected. Every cloud provider will be connected to our premises and also between them ? So if we set command on AWS container to send something to Azure…

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [February 18, 2018, 7:03am UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/3 "2018-02-18T07:03:15Z")

</div>

The IPSec network is only between hosts. The agent opens a websocket connection to the server (at the registration URL), the server does not open a connection to the agents.

---

<div class="post-metadata">

**Author:** ![kevinhooke](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kevinhooke](https://forums.suse.com/u/kevinhooke)\
**Post date:** [February 18, 2018, 5:14pm UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/4 "2018-02-18T17:14:36Z")

</div>

Ok, got it. So if my remote host is a VPS publicly accessible on the internet, what do I need to consider to harden the host and it’s use of the rancher agent? What would stop someone else pointing their rancher-server at my rancher agent and taking control of it or deploying their own apps to my host?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [February 18, 2018, 5:52pm UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/5 "2018-02-18T17:52:15Z")

</div>

Again, the agent opens the connection to the server, not the other way around. So the question is the other way, and the agent must have a valid registration URL/token from that server to connect.

---

<div class="post-metadata">

**Author:** ![kevinhooke](https://avatars.discourse-cdn.com/v4/letter/k/65b543/32.png) [@kevinhooke](https://forums.suse.com/u/kevinhooke)\
**Post date:** [February 18, 2018, 5:56pm UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/6 "2018-02-18T17:56:40Z")

</div>

Ok, and the url/token are in the command from the server where it says ‘Copy, paste, and run the command below to register the host with Rancher’ ?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [February 18, 2018, 8:45pm UTC](https://forums.suse.com/t/security-with-remote-hosts/9538/7 "2018-02-18T20:45:14Z")

</div>

Yes, the token is in the command and is used to give each host a unique API key to talk to the server with.
