# Cannot connect to Elasticsearch endpoint in Azure

**URL:** <https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186>\
**Category:** Elasticsearch\
**Created:** [March 20, 2019, 3:56pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186 "2019-03-20T15:56:27Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 20, 2019, 3:56pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/1 "2019-03-20T15:56:27Z")

</div>

I've deployed an Elasticsearch cluster into Azure using the ARM template and associated script found here: [ARM Template](https://www.elastic.co/guide/en/elastic-stack-deploy/current/azure-arm-template.html). I used default settings, except for the admin user name and password. After deployment succeeded, I am able to connect to Kibana, but I'm unable to make HTTP requests to the cluster on the Kibana machine's IP, port 9200. I'm using Postman to make the request, and I just get a "Could not get any response" message. I have tried both http and https.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b468ff51173db7484bbfd511cd66c90b5a16a57.png)

I have added my IP in the Azure network security group on port 9200 into the Kibana server.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/9/8977333fdfc906f194568ee7b2085a959c4efe23.png)

Any other thoughts on what I could be missing?

---

<div class="post-metadata">

**Author:** ![Michelle\_Bennett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michelle_bennett/32/96142_2.png) [@Michelle\_Bennett](https://discuss.elastic.co/u/Michelle_Bennett)\
**Post date:** [March 20, 2019, 4:06pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/2 "2019-03-20T16:06:50Z")

</div>

Make sure you are hitting the elasticsearch server port 9200 and not the Kibana server. There is nothing listening on 9200 on Kibana server.

---

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 20, 2019, 5:00pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/3 "2019-03-20T17:00:00Z")

</div>

Thanks, Michelle. It was my understanding that the default deployment had the Kibana server set up as a "jumpbox" to act as the gateway for Elasticsearch communication. Is that not correct?

EDIT: Also, my deployment doesn't have an Elastic server. It has the Kibana server and three data servers (data-0, -1, -2). The only public IP in the deployment is for the Kibana server.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/0/904384d1d7276d0a92f0591c5c8669191d43ab27.png)

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [March 21, 2019, 4:46am UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/4 "2019-03-21T04:46:48Z")

</div>

@bo.clifton You have a couple of options if you intend to also expose the Elasticsearch cluster (composed of the data nodes) to the public internet:

1. Deploy an [external loadbalancer](https://www.elastic.co/guide/en/elastic-stack-deploy/current/azure-arm-template-load-balancing.html#external-load-balancer) by using `external` as the value for the `loadBalancerType` parameter

2. Deploy [Application Gateway](https://www.elastic.co/guide/en/elastic-stack-deploy/current/azure-arm-template-load-balancing.html#application-gateway) by using `gateway` as the value for the `loadBalancerType`. Application Gateway has many more parameters to customize the deployment to your needs. From experience, it also takes around 20-30 minutes to deploy.

In both scenarios, an internal load balancer is also deployed, to allow Kibana to communicate with the cluster. By default, the template deploys only an internal load balancer.

**Be careful about exposing Elasticsearch to the public internet; ensure that you have appropriate Authentication and Authorization controls in place, as well as Transport Layer Security**. The Elastic Stack Security features can help with this.

---

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 21, 2019, 3:55pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/5 "2019-03-21T15:55:17Z")

</div>

Thanks, @forloop. That's good information. If I set up an external load balancer in my current deployment (there's already the default internal lb in place), would I be able to forward traffic to a specific place to enable queries? Or is it necessary to rebuild the cluster with external lb in the config?

---

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 21, 2019, 6:57pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/6 "2019-03-21T18:57:22Z")

</div>

@forloop and @Michelle_Bennett I redeployed the cluster with an external load balancer and I'm able to get a response from the endpoint but the response just says I'm missing an auth token. I've tried to follow this article but seem to be missing something. [Article](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-token.html) If I'm not worried about encrypting the traffic FOR NOW, what further steps would you recommend?

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/2/4222632c9bced376138cbf10deab1358047d0b93.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f074d94e04c69b4b24c522e286459c1b2093f23f.png)

---

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 21, 2019, 9:44pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/7 "2019-03-21T21:44:49Z")

</div>

I figured it out. Kind of...I deployed the template with an external load balancer in place with no X-pack plugins. When complete, I can get cluster health from the external IP of the external load balancer.

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/7/97bd12e6f621c4b91f4ff0b7bab6bf2dc779c4dc.png)

Now...if anyone knows how to restrict traffic to only allow from one IP, that would be all I need! (I realize that's probably a separate topic...if it's against forum rules, or if I don't get any answers, I'll move the question somewhere else)

---

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 21, 2019, 11:15pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/8 "2019-03-21T23:15:04Z")

</div>

Solved the last bit...just need to assign the created subnet to the created network security group (default name of kibana-nsg), then create a rule allowing port 9200-9205 (maybe less? 9200-9201 didn't work, but this did...) from your desired IP address. Hope that helps someone!

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [March 21, 2019, 11:56pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/9 "2019-03-21T23:56:35Z")

</div>

To answer your questions @bo.clifton,

> [@bo.clifton](#):
>
> Thanks, @forloop. That's good information. If I set up an external load balancer in my current deployment (there's already the default internal lb in place), would I be able to forward traffic to a specific place to enable queries? Or is it necessary to rebuild the cluster with external lb in the config?

It would be easier to deploy a new cluster with the template, including an external load balancer.

Due to a limitation in Azure load balancers, only a single load balancer can address a backend port on a specified port. When an external load balancer is deployed, an internal load balancer is also deployed to allow Kibana to communicate with the cluster. The internal load balancer communicates with the backend pool on port 9200 meaning that the external load balancer cannot also communicate with the backend pool on port 9200. To work around this, the external load balancer communicates with the backend pool over port 9201 and iptables persistent rules are implemented on each VM to forward to port 9200.

> [@bo.clifton](#):
>
> @forloop and @Michelle_Bennett I redeployed the cluster with an external load balancer and I'm able to get a response from the endpoint but the response just says I'm missing an auth token. I've tried to follow this article but seem to be missing something. [Article](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-token.html) If I'm not worried about encrypting the traffic FOR NOW, what further steps would you recommend?

For authentication with the [native realm](https://www.elastic.co/guide/en/elastic-stack-overview/current/native-realm.html), you send a [Basic Authentication header](https://en.wikipedia.org/wiki/Basic_access_authentication) i.e. a HTTP header with

```sh
Authorization: Basic <credentials>

```

where `<credentials>` is the base 64 encoded form of `<username>:<password>`, where `<username>` is a configured or built-in user (e.g. `elastic`) in Elasticsearch, and `<password>` is the password for that user.

> [@bo.clifton](#):
>
> Solved the last bit...just need to assign the created subnet to the created network security group (default name of kibana-nsg), then create a rule allowing port 9200-9205 (maybe less? 9200-9201 didn't work, but this did...) from your desired IP address. Hope that helps someone!

The template takes care of deploying the necessary subnets and network security groups and associating them with the related resources. If you require limiting to specific IP addresses or sources, you can add additional rules to a deployed network security group to do so.

---

<div class="post-metadata">

**Author:** ![bo.clifton](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bo.clifton](https://discuss.elastic.co/u/bo.clifton)\
**Post date:** [March 22, 2019, 3:28pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/10 "2019-03-22T15:28:23Z")

</div>

@forloop thanks a lot for the detailed info. Here's what I had to do to get everything working for me.

After the deployment with external load balancer, the network security group (NSG) is only set to control the Kibana server NIC. I associated the deployed subnet to the NSG and it was then able to filter the port requests for every device on the subnet. I then added the NSG rule I mentioned above, allowing ports 9200-9205 to pass through from my IP address only. Works like a charm.

Since I'm only going to have requests coming from one IP, I don't believe it's necessary to add encryption and authentication. Do you agree? I'm trying to keep the setup simple, but still robust enough to be reliable and secure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2019, 3:28pm UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-endpoint-in-azure/173186/11 "2019-04-19T15:28:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
