A bridge ends at the edge of its host. An overlay network spans several Docker 514 hosts, so a container on one machine reaches a container on another by name, as if both sat on one switch. Docker builds it with VXLAN: each Ethernet frame between containers is wrapped in a UDP packet (port 4789) and sent across the ordinary network between the hosts, which unwrap it on arrival.

The hosts must agree on which containers live where, and Docker keeps that state in Swarm 514 mode's distributed store. Without a swarm, the driver refuses to work:
docker info --format '{{.Swarm.LocalNodeState}}'
docker network create -d overlay l3-overlayinactive Error response from daemon: This node is not a swarm manager. Use "docker swarm init" or ...
Docker Swarm in 2026 builds a swarm and uses overlays for real. The hosts must allow TCP 2377 (managers), TCP and UDP 7946 (gossip) and UDP 4789 (VXLAN) between them; --attachable lets standalone docker run containers join an overlay that otherwise only Swarm services may use; and --opt encrypted adds IPsec between hosts, at a measurable cost in throughput.