# Security Considerations

**URL:** <https://community.traefik.io/t/security-considerations/573>\
**Category:** Traefik v1\
**Tags:** docker-swarm, traefik-ee\
**Created:** [June 26, 2019, 8:26am UTC](https://community.traefik.io/t/security-considerations/573 "2019-06-26T08:26:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![x-jokay](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/x-jokay/32/313_2.png) [@x-jokay](https://community.traefik.io/u/x-jokay)\
**Post date:** [June 26, 2019, 8:26am UTC](https://community.traefik.io/t/security-considerations/573/1 "2019-06-26T08:26:44Z")

</div>

Hi

When using Traefik as proxy there are some security considerations as mentioned [here](https://docs.traefik.io/configuration/backends/docker/#security-considerations).

Using the workarounds, e.g.

- Accounting at networking level (proxy\_backend network)
- Accounting at container level ("socket exposer" container)

This will separating the control plane ("socket exposer" container with own network) from the data plane (proxy\_backend network) as would it be the case when using TraefikEE as well?

Or is there any benefit from using TraefikEE (beside the support)?

---

<div class="post-metadata">

**Author:** ![Adrienmartinet](https://avatars.discourse-cdn.com/v4/letter/a/b19c9b/32.png) [@Adrienmartinet](https://community.traefik.io/u/Adrienmartinet)\
**Post date:** [June 26, 2019, 10:22am UTC](https://community.traefik.io/t/security-considerations/573/2 "2019-06-26T10:22:01Z")

</div>

Hi x-jokay,  
This is Adrien from Containous.  
Traefik EE has these main features on top of Traefik :

- Clustering/ High Availability
- Scalability:
  - Ability to automatically spin up new data nodes and spin down when needed.
  - Less pressure on k8s (or Swarm) API as only 1 TraefikEE instance watches it at a time (instead of all OSS instances)

- Security:
  - Isolation between Data nodes (that handles the traffic) and the Control nodes (store the configuration).
  - Encrypted Data (including sensitive data as certificates) on each node

- TraefikEE Cuddle
  - Quick deployment with 1 line of code for all orchestrators through the CLI
  - Lean management: switch from staging to production cluster with 1 flag, ensuring the same configuration everywhere
  - Easier Static Configuration management: new static configuration is deployed node per node, no traffic lost

- Distributed Let’s Encrypt : able to share the Let’s Encrypt certificates to all the Data nodes
- Support

happy to continue the discussion / [adrien@containo.us](mailto:adrien@containo.us)
