Overlay Networks

Overlay Networks for Multi-Host Communication

A bridge ends at the edge of its host. An overlay network spans several Docker 514 hosts, so a container on one machine reaches a container on another by name, as if both sat on one switch. Docker builds it with VXLAN: each Ethernet frame between containers is wrapped in a UDP packet (port 4789) and sent across the ordinary network between the hosts, which unwrap it on arrival.

An overlay network carries container traffic between hosts inside VXLAN packets
An overlay network carries container traffic between hosts inside VXLAN packets

The hosts must agree on which containers live where, and Docker keeps that state in Swarm 514 mode's distributed store. Without a swarm, the driver refuses to work:

Overlay networks need Swarm modeShell
docker info --format '{{.Swarm.LocalNodeState}}'
docker network create -d overlay l3-overlay
Output
inactive
Error response from daemon: This node is not a swarm manager. Use "docker swarm init" or ...

Docker Swarm in 2026 builds a swarm and uses overlays for real. The hosts must allow TCP 2377 (managers), TCP and UDP 7946 (gossip) and UDP 4789 (VXLAN) between them; --attachable lets standalone docker run containers join an overlay that otherwise only Swarm services may use; and --opt encrypted adds IPsec between hosts, at a measurable cost in throughput.