# Cluster interface

**URL:** <https://discuss.elastic.co/t/cluster-interface/18723>\
**Category:** Elasticsearch\
**Created:** [July 17, 2014, 5:39pm UTC](https://discuss.elastic.co/t/cluster-interface/18723 "2014-07-17T17:39:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![asrozar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asrozar/32/675_2.png) [@asrozar](https://discuss.elastic.co/u/asrozar)\
**Post date:** [July 17, 2014, 5:39pm UTC](https://discuss.elastic.co/t/cluster-interface/18723/1 "2014-07-17T17:39:12Z")

</div>

I've setup three kvm guests with elasticsearch in a cluster. Since iptables  
kills the cluster but I'd like to maintain some security I've setup the  
main host with eth0 bridged so I can get to it, and eth1 on the default nat  
interface. The other two hosts use eth1 on the same nat interface. The idea  
is That I can (hopefully) use iptables on eth0 for the main host, and let  
elasticsearch cluster on eth1 (from main) and the other two on eth0 without  
iptables. Not working as I'd expect it too. Is there a for clustering on  
specific interfaces?

Thanks,  
Avery

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 17, 2014, 11:37pm UTC](https://discuss.elastic.co/t/cluster-interface/18723/2 "2014-07-17T23:37:46Z")

</div>

ES needs direct access to the interface for the instance, so NAT won't work.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 18 July 2014 03:39, [avery.rozar@insecure-it.com](mailto:avery.rozar@insecure-it.com) wrote:

> I've setup three kvm guests with elasticsearch in a cluster. Since  
> iptables kills the cluster but I'd like to maintain some security I've  
> setup the main host with eth0 bridged so I can get to it, and eth1 on the  
> default nat interface. The other two hosts use eth1 on the same nat  
> interface. The idea is That I can (hopefully) use iptables on eth0 for the  
> main host, and let elasticsearch cluster on eth1 (from main) and the other  
> two on eth0 without iptables. Not working as I'd expect it too. Is there a  
> for clustering on specific interfaces?
> 
> Thanks,  
> Avery
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624bYesEhd6jyfFZYSp1vAOx1S1tG\_hbg29vAQJBBJOfSyg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624bYesEhd6jyfFZYSp1vAOx1S1tG_hbg29vAQJBBJOfSyg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![asrozar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asrozar/32/675_2.png) [@asrozar](https://discuss.elastic.co/u/asrozar)\
**Post date:** [July 18, 2014, 12:05pm UTC](https://discuss.elastic.co/t/cluster-interface/18723/3 "2014-07-18T12:05:00Z")

</div>

But all three hosts have an interface on the NAT network (same layer 2).  
Only one host has 2 NICs, one on the NATed network and one accessible by me.

Is there a way to force clustering on a specific interface? In my case, the  
NATed network?

On Thursday, July 17, 2014 7:38:21 PM UTC-4, Mark Walkom wrote:

> ES needs direct access to the interface for the instance, so NAT won't  
> work.
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 18 July 2014 03:39, \<[avery...@insecure-it.com](mailto:avery...@insecure-it.com) \<javascript:\>\> wrote:
> 
> > I've setup three kvm guests with elasticsearch in a cluster. Since  
> > iptables kills the cluster but I'd like to maintain some security I've  
> > setup the main host with eth0 bridged so I can get to it, and eth1 on the  
> > default nat interface. The other two hosts use eth1 on the same nat  
> > interface. The idea is That I can (hopefully) use iptables on eth0 for the  
> > main host, and let elasticsearch cluster on eth1 (from main) and the other  
> > two on eth0 without iptables. Not working as I'd expect it too. Is there a  
> > for clustering on specific interfaces?
> > 
> > Thanks,  
> > Avery
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 18, 2014, 12:17pm UTC](https://discuss.elastic.co/t/cluster-interface/18723/4 "2014-07-18T12:17:00Z")

</div>

Yep -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 18 July 2014 22:05, [avery.rozar@insecure-it.com](mailto:avery.rozar@insecure-it.com) wrote:

> But all three hosts have an interface on the NAT network (same layer 2).  
> Only one host has 2 NICs, one on the NATed network and one accessible by me.
> 
> Is there a way to force clustering on a specific interface? In my case,  
> the NATed network?
> 
> On Thursday, July 17, 2014 7:38:21 PM UTC-4, Mark Walkom wrote:
> 
> > ES needs direct access to the interface for the instance, so NAT won't  
> > work.
> > 
> > Regards,  
> > Mark Walkom
> > 
> > Infrastructure Engineer  
> > Campaign Monitor  
> > email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com)  
> > web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> > 
> > On 18 July 2014 03:39, [avery...@insecure-it.com](mailto:avery...@insecure-it.com) wrote:
> > 
> > > I've setup three kvm guests with elasticsearch in a cluster. Since  
> > > iptables kills the cluster but I'd like to maintain some security I've  
> > > setup the main host with eth0 bridged so I can get to it, and eth1 on the  
> > > default nat interface. The other two hosts use eth1 on the same nat  
> > > interface. The idea is That I can (hopefully) use iptables on eth0 for the  
> > > main host, and let elasticsearch cluster on eth1 (from main) and the other  
> > > two on eth0 without iptables. Not working as I'd expect it too. Is there a  
> > > for clustering on specific interfaces?
> > > 
> > > Thanks,  
> > > Avery
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624aSTjaL\_hf0QRYzsBVUjuC8FESJ%3DZjHGfYZqcWe5aOwBg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624aSTjaL_hf0QRYzsBVUjuC8FESJ%3DZjHGfYZqcWe5aOwBg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![asrozar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asrozar/32/675_2.png) [@asrozar](https://discuss.elastic.co/u/asrozar)\
**Post date:** [July 18, 2014, 1:20pm UTC](https://discuss.elastic.co/t/cluster-interface/18723/5 "2014-07-18T13:20:44Z")

</div>

Thanks!

On Friday, July 18, 2014 8:17:32 AM UTC-4, Mark Walkom wrote:

> Yep -  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/modules-network.html)
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 18 July 2014 22:05, \<[avery...@insecure-it.com](mailto:avery...@insecure-it.com) \<javascript:\>\> wrote:
> 
> > But all three hosts have an interface on the NAT network (same layer 2).  
> > Only one host has 2 NICs, one on the NATed network and one accessible by me.
> > 
> > Is there a way to force clustering on a specific interface? In my case,  
> > the NATed network?
> > 
> > On Thursday, July 17, 2014 7:38:21 PM UTC-4, Mark Walkom wrote:
> > 
> > > ES needs direct access to the interface for the instance, so NAT won't  
> > > work.
> > > 
> > > Regards,  
> > > Mark Walkom
> > > 
> > > Infrastructure Engineer  
> > > Campaign Monitor  
> > > email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com)  
> > > web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> > > 
> > > On 18 July 2014 03:39, [avery...@insecure-it.com](mailto:avery...@insecure-it.com) wrote:
> > > 
> > > > I've setup three kvm guests with elasticsearch in a cluster. Since  
> > > > iptables kills the cluster but I'd like to maintain some security I've  
> > > > setup the main host with eth0 bridged so I can get to it, and eth1 on the  
> > > > default nat interface. The other two hosts use eth1 on the same nat  
> > > > interface. The idea is That I can (hopefully) use iptables on eth0 for the  
> > > > main host, and let elasticsearch cluster on eth1 (from main) and the other  
> > > > two on eth0 without iptables. Not working as I'd expect it too. Is there a  
> > > > for clustering on specific interfaces?
> > > > 
> > > > Thanks,  
> > > > Avery
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > > msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%  
> > > > [40googlegroups.com](http://40googlegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b8cd8755-ff2c-4925-8af9-b3061e05365e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3684c95b-23b0-4524-8716-db99e44d81b6%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/45c94fd8-ff2e-46a0-8eed-ef4631e6f4c6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/45c94fd8-ff2e-46a0-8eed-ef4631e6f4c6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:14am UTC](https://discuss.elastic.co/t/cluster-interface/18723/6 "2017-07-06T01:14:55Z")

</div>


