# Connecting DMZ ENV to ELK in the LAN

**URL:** https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643
**Category:** Beats
**Created:** [December 11, 2016, 1:47pm UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643 "2016-12-11T13:47:32Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)
#### Post date: [December 11, 2016, 1:47pm UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/1 "2016-12-11T13:47:32Z")

</div>

Hi there  
we have an ELK STACK in our LAN env (internal environment)  
we also have a DMZ env in the organization  
we want to install beats (metric winlog file...) on every server in the DMZ env  
and we want the output to get to the ELK in the LAN  
i read that you can use redis for that ( and configure in the beat YAML a redis output)  
but i also read that you can use reverse proxy - BTW - how can we set that up?

are there any other options?  
what is the best one?

BTW - we plan on installing X-PACK license soon

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 12, 2016, 1:56pm UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/2 "2016-12-12T13:56:05Z")

</div>

You probably have different options here. If you write to redis or kafka first, you can use Logstash from your LAN to access redis / kafka to fetch the data. If the reverse proxy setup with the elasticsearch output will work perhaps @steffens can give some more details?

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [December 12, 2016, 2:15pm UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/3 "2016-12-12T14:15:52Z")

</div>

I'd prefer a queueing system like redis/kafka to have a separate single point of contact between the subnetworks. But a reverse proxy should work as well. Advantage of queuing system is, if ES is not reachable, data can still be pushed to queue.

Given you're having 2 separate networks, some consideration about access rights to queueing system or reverse proxy should taken into account.

---

<div class="post-metadata">

### Author: ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)
#### Post date: [December 12, 2016, 2:31pm UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/4 "2016-12-12T14:31:24Z")

</div>

Hi  
thanks @ruflin @steffens for your replies  
i think the redis solution would be better for us since we can use logstash

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 13, 2016, 8:10am UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/5 "2016-12-13T08:10:15Z")

</div>

@gilisade Logstash supports Redis and Kafka. Also be aware the Logstash has since 5.1 a persistent queue itself: [https://www.elastic.co/guide/en/logstash/5.1/persistent-queues.html](https://www.elastic.co/guide/en/logstash/5.1/persistent-queues.html)

---

<div class="post-metadata">

### Author: ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)
#### Post date: [December 13, 2016, 8:27am UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/6 "2016-12-13T08:27:57Z")

</div>

Do you suggest we work with both redis and persistent queue ? Or push events directly to logstash with beats and use the persistent queue ?

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 13, 2016, 8:32am UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/7 "2016-12-13T08:32:00Z")

</div>

I would say in the case of Redis you can only use logstash with the persistent queue. If you need a distributed queue, I would go with Kafka and LS.

---

<div class="post-metadata">

### Author: ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)
#### Post date: [December 13, 2016, 9:32am UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/8 "2016-12-13T09:32:48Z")

</div>

What if we install logstash on the proxy server (between the dmz and the lan) beats from dmz will write to this logstash (with persistent queue) and this logstash writes directly to ES in the lan (we just open one port between logstash and ES) ?  
Is that option preferable?

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [December 13, 2016, 11:04am UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/9 "2016-12-13T11:04:19Z")

</div>

Sounds like a valid approach.

With the proxy server being crucial for networks to operate correctly, I'd consider putting logstash on another machine within the protected network and simply forward/proxy the TCP connection.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 1, 2017, 1:47pm UTC](https://discuss.elastic.co/t/connecting-dmz-env-to-elk-in-the-lan/68643/10 "2017-01-01T13:47:39Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
