When you provision a {{page.netscaler-cpx-short}} instance on a Docker host, the Docker engine creates a virtual interface, eth0, on the CPX instance. This eth0 interface is directly connected to a virtual interface (veth*) on the docker0 bridge. The Docker engine also assigns an IP address to the {{page.netscaler-cpx-short}} instance in the network 172.17.0.0/16.
The default gateway for the CPX instance is the IP address of the docker0 bridge, which means that any communication with the {{page.netscaler-cpx-short}} instance is done through the Docker network. All incoming traffic received from the docker0 bridge is received by the eth0 interface on the {{page.netscaler-cpx-short}} instance and processed by the {{page.netscaler-cpx-short}} packet engine.
The following figure illustrates the architecture of a {{page.netscaler-cpx-short}} instance on a Docker host.