# Elasticsearch Ip restriction using NGINX

**URL:** <https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145>\
**Category:** Elasticsearch\
**Created:** [June 28, 2017, 4:00pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145 "2017-06-28T16:00:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [June 28, 2017, 4:00pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/1 "2017-06-28T16:00:11Z")

</div>

Hi,

I have elasticsearch instance running in my linux server on xxx.xxx.1.75: 9201.

I have installed and configured NGINX on another server xxx.xx.1.89 and set the proxy for the elasticsearch to be running on port 5001i.e., it is able to access from xxx.xxx.1.89:5001.

But when I try to access the elasticsearch using port xxx.xxx.1.75:9201 it is running good, which I don't want to happen.

I want to restrict the access of elasticsearch cluster only through NGINX reverse proxy server i.e., xxx.xx.1.89:5001 but not directly from xxx.xx.1.75:9201.

Please help me to solve this.

thanks.

---

<div class="post-metadata">

**Author:** ![niraj\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_kumar/32/4130_2.png) [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Post date:** [June 29, 2017, 4:50pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/2 "2017-06-29T16:50:57Z")

</div>

> [@navyagoli](#):
>
> to be runnin

Can you describe more about your environment? Like whether it is on cloud, on-premise infra.

If you are on cloud like AWS, GCE , Azure you can restrict the data layer ( ES ) using security groups, to be accessible only from the nginx which will be your public facing server.

I am not sure whether you can do it on an on-premise with no access to firewall. If you can nginx on the same instance where ES is installed you can make elasticsearch listen on localhost instead of IP and route nginx proxy to 127.0.0.1:9201 instead. Which will allow only nginx to talk to elasticsearch.

--  
Niraj

---

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [June 30, 2017, 8:14am UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/3 "2017-06-30T08:14:57Z")

</div>

My environment is an on premise environment.

Is there any way to change elasticsearch.yml file by changing "http.host " so that elasticsearch is restricted by nginx of other server.

I have tried with http.host: 127.0.0.1 in elasticsearch.yml and configured that in nginx.conf as 127.0.0.1:9001 previously and it is working fine.

The only thing I want to do is to access this elasticsearch from other nginx reverse proxy server.

Help me solve this.

thanks

---

<div class="post-metadata">

**Author:** ![niraj\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_kumar/32/4130_2.png) [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Post date:** [June 30, 2017, 10:01pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/4 "2017-06-30T22:01:40Z")

</div>

Well you can try a iptables trick something like this.

iptables -A INPUT -p tcp --dport 22 -s YourIP -j ACCEPT  
iptables -A INPUT -p tcp --dport 22 -j DROP

Replace the port 22 with the elasticsearch port and YOUR IP with IP of nginx.

---

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [July 3, 2017, 1:25pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/5 "2017-07-03T13:25:33Z")

</div>

I used the command :

sudo firewall-cmd --zone=trusted --add-source=xxx.xx.1.75 to allow the traffic from elasticsearch to the NGINX server on xxx.xx.1.89.

And tried to access it through nginx by specifying it in nginx.conf.

Still it show 502 BAD Gateway error.

---

<div class="post-metadata">

**Author:** ![niraj\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_kumar/32/4130_2.png) [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Post date:** [July 3, 2017, 4:21pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/6 "2017-07-03T16:21:09Z")

</div>

Did you try telnetting from nginx server to check whether nginx can talk to that port. And also trying it from different system whether the firewall actually worked.

---

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [July 4, 2017, 4:20pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/7 "2017-07-04T16:20:02Z")

</div>

Thank you very much for the assistance.

I followed your suggestions and resolved the issue.

---

<div class="post-metadata">

**Author:** ![niraj\_kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niraj_kumar/32/4130_2.png) [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Post date:** [July 5, 2017, 6:14pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/8 "2017-07-05T18:14:37Z")

</div>

Glad it worked for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 6:14pm UTC](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145/9 "2017-08-02T18:14:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
