Back to articles
Technology Insight

Securing Docker Swarm Internal Networks: Implementing Wire-Speed IPsec Encryption Between VPS Nodes

June 4, 2026

Introduction: The Hidden Security Risks in Multi-Node Docker Swarm Deployments

Docker Swarm has earned its reputation as an incredibly efficient, user-friendly container orchestration platform. For many businesses, deploying a Swarm cluster across multiple Virtual Private Servers (VPS) is the default strategy for achieving high availability and scalability. However, when these VPS nodes communicate with each other over public clouds or shared data center networks, a critical vulnerability emerges: inter-node traffic is transmitted in cleartext by default.

Without explicit security measures, sensitive data—including database queries, API keys, and proprietary business logic—moves across the internet or untrusted provider networks vulnerable to packet sniffing, man-in-the-middle (MitM) attacks, and unauthorized data interception. To mitigate this risk, enterprise architectures require network-layer security. This blog post provides an in-depth, technical guide to securing your Docker Swarm internal network by enabling native IPsec (Internet Protocol Security) encryption at the network overlay layer.

---

Understanding Docker Swarm Overlay Networks and IPsec

To understand how to secure the cluster, we must first examine how Docker Swarm handles multi-host networking. Swarm relies on overlay networks, which utilize Virtual Extensible LAN (VXLAN) encapsulation to create a virtual layer-2 network on top of an existing layer-3 infrastructure. This allows containers running on completely different VPS hosts to communicate as if they were attached to the exact same physical switch.

While VXLAN handles connectivity beautifully, it does not provide confidentiality or integrity. That is where IPsec comes in. Docker Swarm integrates native support for IPsec within its overlay network driver. When activated, Docker utilizes the Linux kernel's built-in IPsec ESP (Encapsulating Security Payload) in transport mode. This ensures that:

  • Confidentiality: All traffic encapsulated within the VXLAN tunnel is encrypted using strong cryptographic algorithms (AES-GCM).
  • Data Integrity: Packets cannot be modified in transit without detection.
  • Authentication: Only validated cryptographic keys managed automatically by the Swarm manager nodes can encrypt and decrypt the traffic.
Key Architecture Advantage: Because encryption happens directly at the Linux kernel level via IPsec, cryptographic operations are highly optimized, resulting in minimal CPU overhead compared to application-layer TLS proxies.
---

Prerequisites for Production Implementation

Before modifying your production network topology, ensure your infrastructure satisfies the following essential requirements:

  1. Docker Engine Version: All nodes must run Docker Engine 17.06 or higher (modern stable releases are highly recommended).
  2. Kernel Support: The underlying VPS operating systems (e.g., Ubuntu, Debian, RHEL) must have the xfrm_user and crypto kernel modules active. These are enabled by default on almost all modern cloud kernels.
  3. Firewall Configuration: Your VPS firewall rules (UFW, firewalld, or cloud security groups) must permit the following traffic between all cluster nodes:
    • UDP port 4789 (for data plane VXLAN traffic)
    • IP Protocol 50 (ESP) – absolute necessity for IPsec data transport
---

Step-by-Step Guide: Creating an Encrypted Overlay Network

Enabling IPsec encryption in Docker Swarm does not require complex IPSec tools like StrongSwan or OpenSwan. Docker handles the key exchange and rotation automatically via its internal Raft consensus mechanism. Follow these steps to implement encryption:

Step 1: Initializing or Verifying Your Swarm Cluster

If you have not already initialized your Swarm, run the following command on your primary manager node, ensuring you bind to the correct public or private network interface:

docker swarm init --advertise-addr 

Join your worker nodes to the cluster using the token provided by the initialization output.

Step 2: Provisioning the Encrypted Overlay Network

To create a network with IPsec enabled, you must append the --opt encrypted flag during the network creation process. Execute the following command on a manager node:

docker network create \
  --driver overlay \
  --opt encrypted \
  --attachable \
  secure_prod_network

The --opt encrypted flag instructs the Swarm managers to provision IPsec tunnels dynamically whenever two nodes need to exchange traffic for containers attached to secure_prod_network.

Step 3: Deploying Services and Verifying Connectivity

Now, deploy your application services onto the newly created network. For example, let us deploy an Nginx web server and a backend service to test connectivity:

docker service create --name web-server --network secure_prod_network -p 80:80 nginx:latest

Docker Swarm will automatically distribute these tasks across available VPS nodes, establishing secure IPsec tunnels completely transparently to the applications running inside the containers.

---

Verifying and Validating IPsec Traffic Inspection

In cybersecurity, verification is a core principle. To confirm that your network traffic is actually encrypted and not traversing the public internet in plain text, you can inspect raw network packets using tcpdump on one of your VPS nodes.

Run the following command on a host interface (e.g., eth0) while your services are actively communicating:

sudo tcpdump -ni eth0 ip proto 50

If encryption is operating correctly, you will observe a stream of ESP (Encapsulating Security Payload) packets moving between your node IPs. If you attempt to capture standard VXLAN data on UDP port 4789, you should see no unencrypted packets, confirming that all container-to-container communication is wrapped safely inside the IPsec layer.

---

Performance Implications and Best Practices

While native IPsec encryption is highly efficient, introducing any cryptographic layer affects system resources. Organizations should consider the following best practices to maximize both security and throughput:

1. Hardware Acceleration (AES-NI)

Ensure that your VPS providers offer CPUs supporting AES-NI (Advanced Encryption Standard New Instructions). Hardware acceleration allows the CPU to process IPsec encryption algorithms at the hardware level, preventing performance bottlenecks and keeping CPU utilization low even under high network loads.

2. Managing MTU (Maximum Transmission Unit) Overhead

IPsec encapsulation adds bytes to every network packet header. Standard Ethernet networks use an MTU of 1500 bytes. Because VXLAN adds 50 bytes and IPsec ESP adds around 54-60 bytes, default packets can exceed standard boundaries, leading to packet fragmentation and severe performance degradation.

Recommendation: Explicitly adjust your overlay network's MTU during creation if you notice dropping packets or latency spikes:

docker network create --driver overlay --opt encrypted --opt mtu=1400 secure_prod_network

3. Automatic Key Rotation

Docker Swarm automatically handles the rotation of data path symmetric keys every 24 hours. However, security compliance policies may demand tighter controls. You can manually force a key rotation across the entire Swarm cluster at any time using the following command:

docker swarm update --rotate-expiry 12h
---

Conclusion: Zero-Trust Container Infrastructure

Securing internal communication is an absolute requirement in contemporary infrastructure architecture. By simply applying the --opt encrypted flag to Docker Swarm overlay networks, you implement an institutional Zero-Trust network architecture across your distributed VPS nodes. Traffic is shielded from network sniffers, host boundaries are validated through cryptography, and compliance postures are vastly improved—all without needing to refactor a single line of your application code.

As threats targeting cloud architectures grow more sophisticated, layering network-level IPsec defense ensures your Docker Swarm deployments remain resilient, confidential, and compliant.

Securing Docker Swarm Internal Networks: Implementing Wire-Speed IPsec Encryption Between VPS Nodes | DPTCloud