# Disable HTTP OPTIONS on port 9200

**URL:** <https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824>\
**Category:** Endpoint Security\
**Created:** [July 26, 2024, 6:33am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824 "2024-07-26T06:33:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhupendra.mskhatri](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@bhupendra.mskhatri](https://discuss.elastic.co/u/bhupendra.mskhatri)\
**Post date:** [July 26, 2024, 6:33am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/1 "2024-07-26T06:33:23Z")

</div>

How to disable HTTP OPTIONS on port 9200 which our scan tool is flagging as a vulnerability.  
If we cannot, could you please share a reason that I could share with my security team (link to a document would be prefarable)

---

<div class="post-metadata">

**Author:** ![Musab\_Dogan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/musab_dogan/32/70691_2.png) [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Post date:** [July 28, 2024, 10:35pm UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/2 "2024-07-28T22:35:50Z")

</div>

You can update `http.port: 9200` in elasticsearch.yml. Please note that your application must connect with Elasticsearch through a port and by default it's set to 9200.

If the concern related to a browser check the [CORS settings.](https://www.elastic.co/guide/en/elasticsearch/reference/current/behavioral-analytics-cors.html)

---

<div class="post-metadata">

**Author:** ![bhupendra.mskhatri](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@bhupendra.mskhatri](https://discuss.elastic.co/u/bhupendra.mskhatri)\
**Post date:** [July 29, 2024, 1:11am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/3 "2024-07-29T01:11:20Z")

</div>

Thankyou for response @Musab_Dogan  
The issue is our security tool scans through all the ports and is able to identify that 9200 has OPTIONS enabled.  
Even if we change port, it will get highlighted in the next scan cycle.  
We would like a way where we could disable the OPTIONS method like we can do it for apachec/jetty/iis.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 29, 2024, 2:46am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/4 "2024-07-29T02:46:27Z")

</div>

> [@bhupendra.mskhatri](#):
>
> We would like a way where we could disable the OPTIONS method like we can do it for apachec/jetty/iis.

This is not possible, you cannot disable any http method on Elasticsearch.

---

<div class="post-metadata">

**Author:** ![bhupendra.mskhatri](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@bhupendra.mskhatri](https://discuss.elastic.co/u/bhupendra.mskhatri)\
**Post date:** [July 29, 2024, 3:07am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/5 "2024-07-29T03:07:39Z")

</div>

Thankyou @leandrojmp .  
And would it be correct to claim that all http methods on port 9200 are safe i.e. any malicious attack using the http methods on port 9200 is difficult (if not impossible) as access to this port is password protected?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 29, 2024, 4:03am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/6 "2024-07-29T04:03:27Z")

</div>

Making an OPTIONS request to Elasticsearch does not require any authentication, it will return which methods are supported in each API endpoint.

Some endpoints will support GET, others will support GET and POST, which depends on each endpoints.

> [@bhupendra.mskhatri](#):
>
> And would it be correct to claim that all http methods on port 9200 are safe i.e. any malicious attack using the http methods on port 9200 is difficult (if not impossible) as access to this port is password protected?

No, this is not correct because some unknown vulnerability may arise that could be exploited.

Being safe or unsafe depend on other factors like if security is configured, if the password used are strong, if the your endpoint is not publicly exposed to the internet, if the stack is up to date, multiple things can make your cluster more safe or unsafe.

Many security scan tools will alert if an HTTP endpoint has the OPTIONS method allowed because this method can be used to know what other methods are supported, but this can also be done in multiple other ways, so this alert is normally just an information alert.

Since you cannot disable OPTIONS in elasticsearch you need to adjust your security scan tool to ignore it in this case.

---

<div class="post-metadata">

**Author:** ![bhupendra.mskhatri](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@bhupendra.mskhatri](https://discuss.elastic.co/u/bhupendra.mskhatri)\
**Post date:** [July 29, 2024, 4:16am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/7 "2024-07-29T04:16:02Z")

</div>

@leandrojmp thanks a lot.  
That explanation is real helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2024, 4:16am UTC](https://discuss.elastic.co/t/disable-http-options-on-port-9200/363824/8 "2024-08-26T04:16:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
