Docker IPvlan L2 vs L3 Network Driver Configuration - 夜莺博客

Docker IPvlan L2 vs L3 Network Driver Configuration

IPvlan gives containers addresses on the physical network instead of the host's NAT range, which removes a hairpin hop and, in L3 mode, removes the broadcast domain entirely. The trade-off is that the host cannot talk to its own containers through the parent interface, and L2 mode silently drops cross-subnet traffic unless a router exists. This guide covers the three modes, the network creation syntax for each, and the design constraints that decide which one is right for a given host.

Why IPvlan Instead of Macvlan

Macvlan assigns each container its own MAC address, which many switches - and most wireless access points - limit to a handful of addresses per port. IPvlan shares the parent interface's MAC address and distinguishes containers by IP, so it passes those limits while still giving containers routable addresses. It also gives complete control over IPv4 and IPv6 addressing, and VLAN tagging can be pushed up to the parent link.

L2 Mode: Same Broadcast Domain

L2 is the default mode and behaves like a switch port: containers use the same subnet as the parent interface and rely on the physical network's gateway.

docker network create -d ipvlan   --subnet=192.168.1.0/24   --gateway=192.168.1.1   -o ipvlan_mode=l2   -o parent=eth0 db_net

docker run -it --rm --network db_net --ip 192.168.1.50 alpine sh

Two subnets on the same parent in L2 mode cannot reach each other - the mode does not route, and there is no broadcast path between them. The usual arrangement is a tagged parent interface per VLAN:

docker network create -d ipvlan   --subnet=192.168.30.0/24 --gateway=192.168.30.1   -o parent=eth0.30 -o ipvlan_mode=l2 vlan30

L3 Mode: Route at the Host

L3 mode makes the host a router for its own containers. Broadcast and multicast are not forwarded at all, which is why L3 mode scales predictably - there is no bridging domain to loop. It also means the container's subnet must differ from the parent interface's subnet, and the default route points at the container's own eth0 device rather than a next hop.

docker network create -d ipvlan   --subnet=192.168.214.0/24 --subnet=10.1.214.0/24   -o ipvlan_mode=l3 ipnet214

# inside the container
ip route
# default dev eth0
# 192.168.214.0/24 dev eth0 src 192.168.214.10

Note that no --gateway is accepted in L3 mode; the field is ignored. Because the host routes for the containers, upstream devices need a route back to the container subnets, and the host must have IP forwarding enabled - including the kernel's ip_forward sysctl and any host firewall policy that would otherwise drop forwarded packets.

The l3s Mode

l3s is a variant that keeps per-container routing but makes the host respond to ARP for the container addresses, which helps legacy peers that insist on resolving every address in the destination subnet before sending. Choose it when L3 works for internal traffic but an upstream appliance cannot be given static routes.

Dual Stack and VLAN Parents

docker network create -d ipvlan   --subnet=192.168.140.0/24 --gateway=192.168.140.1   --ipv6 --subnet=2001:db8:abc9::/64 --gateway=2001:db8:abc9::1   -o parent=eth0.140 -o ipvlan_mode=l2 ipvlan140

Any valid interface can be the parent - eth0, bond0, or a tagged sub-interface - but never loopback. Omit -o parent= entirely and Docker creates a dummy link, which isolates the containers from everything outside the host, the same effect as the --internal flag.

Failure Modes to Expect

Container cannot reach the host. Expected in IPvlan: the parent interface intentionally does not talk to its own children. Use a separate management interface for host communication.

Cross-subnet traffic disappears. L2 mode does not route. Either add an external router or switch to L3 mode.

Remote hosts cannot reach containers. Missing return route on the upstream network, or IP forwarding disabled on the Docker host.

Works on the host, not from outside. Container firewall or cloud security group applying to the parent interface, not to the container address.

For the driver comparison including macvlan and overlay, see Docker networking drivers: bridge, macvlan and overlay, and for the kernel primitives underneath, Linux network namespaces and veth pairs.

原文链接:https://docs.docker.com/engine/network/drivers/ipvlan/