# Elasticsearch server

**URL:** <https://discuss.elastic.co/t/elasticsearch-server/6778>\
**Category:** Elasticsearch\
**Created:** [February 22, 2012, 5:31am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778 "2012-02-22T05:31:32Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abhishek\_Jajoria](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Jajoria](https://discuss.elastic.co/u/Abhishek_Jajoria)\
**Post date:** [February 22, 2012, 5:31am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/1 "2012-02-22T05:31:32Z")

</div>

My elasticsearch server detects other clusters which are running in  
the same network similarly other server detects my cluster. How can I  
configure the elasticsearch.yml so that no other server can detect my  
cluster.

---

<div class="post-metadata">

**Author:** ![kalyan\_sweta](https://avatars.discourse-cdn.com/v4/letter/k/977dab/32.png) [@kalyan\_sweta](https://discuss.elastic.co/u/kalyan_sweta)\
**Post date:** [February 22, 2012, 5:38am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/2 "2012-02-22T05:38:24Z")

</div>

By Setting ur cluster name in elasticsearch.yml  
Eg : cluster.name: clustername

On Wed, Feb 22, 2012 at 11:01 AM, jajoria abhishek \<  
[jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com)\> wrote:

> My elasticsearch server detects other clusters which are running in  
> the same network similarly other server detects my cluster. How can I  
> configure the elasticsearch.yml so that no other server can detect my  
> cluster.

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [February 24, 2012, 1:32pm UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/3 "2012-02-24T13:32:59Z")

</div>

Or, disalbe multicast and use unicast discovery.

On Wednesday, February 22, 2012 at 7:38 AM, sweta kalyan wrote:

> By Setting ur cluster name in elasticsearch.yml  
> Eg : cluster.name ([http://cluster.name](http://cluster.name)): clustername
> 
> On Wed, Feb 22, 2012 at 11:01 AM, jajoria abhishek \<[jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com) ([mailto:jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com))\> wrote:
> 
> > My elasticsearch server detects other clusters which are running in  
> > the same network similarly other server detects my cluster. How can I  
> > configure the elasticsearch.yml so that no other server can detect my  
> > cluster.

---

<div class="post-metadata">

**Author:** ![Abhishek\_Jajoria](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Jajoria](https://discuss.elastic.co/u/Abhishek_Jajoria)\
**Post date:** [February 25, 2012, 11:48am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/4 "2012-02-25T11:48:02Z")

</div>

By disabling the multicast discovery can other network elasticserver can  
acess my indexes by specifying the port and adress in the client  
client = new TransportClient().addTransportAddress(new  
InetSocketTransportAddress(192.168.5.212,9300));

On Fri, Feb 24, 2012 at 7:02 PM, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:

> Or, disalbe multicast and use unicast discovery.
> 
> On Wednesday, February 22, 2012 at 7:38 AM, sweta kalyan wrote:
> 
> By Setting ur cluster name in elasticsearch.yml  
> Eg : cluster.name: clustername
> 
> On Wed, Feb 22, 2012 at 11:01 AM, jajoria abhishek \<  
> [jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com)\> wrote:
> 
> My elasticsearch server detects other clusters which are running in  
> the same network similarly other server detects my cluster. How can I  
> configure the elasticsearch.yml so that no other server can detect my  
> cluster.

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [February 26, 2012, 7:36pm UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/5 "2012-02-26T19:36:23Z")

</div>

Yes.

On Saturday, February 25, 2012 at 1:48 PM, jajoria abhishek wrote:

> By disabling the multicast discovery can other network elasticserver can acess my indexes by specifying the port and adress in the client  
> client = new TransportClient().addTransportAddress(new InetSocketTransportAddress(192.168.5.212,9300));
> 
> On Fri, Feb 24, 2012 at 7:02 PM, Shay Banon \<[kimchy@gmail.com](mailto:kimchy@gmail.com) ([mailto:kimchy@gmail.com](mailto:kimchy@gmail.com))\> wrote:
> 
> > Or, disalbe multicast and use unicast discovery.
> > 
> > On Wednesday, February 22, 2012 at 7:38 AM, sweta kalyan wrote:
> > 
> > > By Setting ur cluster name in elasticsearch.yml  
> > > Eg : cluster.name ([http://cluster.name](http://cluster.name)): clustername
> > > 
> > > On Wed, Feb 22, 2012 at 11:01 AM, jajoria abhishek \<[jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com) ([mailto:jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com))\> wrote:
> > > 
> > > > My elasticsearch server detects other clusters which are running in  
> > > > the same network similarly other server detects my cluster. How can I  
> > > > configure the elasticsearch.yml so that no other server can detect my  
> > > > cluster.

---

<div class="post-metadata">

**Author:** ![Abhishek\_Jajoria](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Jajoria](https://discuss.elastic.co/u/Abhishek_Jajoria)\
**Post date:** [February 27, 2012, 6:45am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/6 "2012-02-27T06:45:18Z")

</div>

But that's the security issue by accessing my indexes other network can  
delete it or modify it I want to make my cluster safe from other clusters  
in the network so that no other network can access my cluster or can read  
data from the indexes how can I do that in ES.

On Mon, Feb 27, 2012 at 1:06 AM, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:

> Yes.
> 
> On Saturday, February 25, 2012 at 1:48 PM, jajoria abhishek wrote:
> 
> By disabling the multicast discovery can other network elasticserver can  
> acess my indexes by specifying the port and adress in the client  
> client = new TransportClient().addTransportAddress(new  
> InetSocketTransportAddress(192.168.5.212,9300));
> 
> On Fri, Feb 24, 2012 at 7:02 PM, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:
> 
> Or, disalbe multicast and use unicast discovery.
> 
> On Wednesday, February 22, 2012 at 7:38 AM, sweta kalyan wrote:
> 
> By Setting ur cluster name in elasticsearch.yml  
> Eg : cluster.name: clustername
> 
> On Wed, Feb 22, 2012 at 11:01 AM, jajoria abhishek \<  
> [jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com)\> wrote:
> 
> My elasticsearch server detects other clusters which are running in  
> the same network similarly other server detects my cluster. How can I  
> configure the elasticsearch.yml so that no other server can detect my  
> cluster.

---

<div class="post-metadata">

**Author:** ![Mark\_Waddle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_waddle/32/2608_2.png) [@Mark\_Waddle](https://discuss.elastic.co/u/Mark_Waddle)\
**Post date:** [February 27, 2012, 8:54am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/7 "2012-02-27T08:54:17Z")

</div>

Have you considered configuring that at the OS network configuration level using iptables or something similar?

---

<div class="post-metadata">

**Author:** ![Abhishek\_Jajoria](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Jajoria](https://discuss.elastic.co/u/Abhishek_Jajoria)\
**Post date:** [February 27, 2012, 10:41am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/8 "2012-02-27T10:41:41Z")

</div>

Sir,  
I can't debarred other systems to connect to my network but I also do not  
want them to access my elasticserver cluster in any form by specifying the  
port and server.

client = new TransportClient().addTransportAddress(new  
InetSocketTransportAddress(IndexserverName.toString(),port));  
It is very difficult to configure that on OS network.  
Is it possible in any from in ES configure level?

On Mon, Feb 27, 2012 at 2:24 PM, Mark Waddle [mark@markwaddle.com](mailto:mark@markwaddle.com) wrote:

> Have you considered configuring that at the OS network configuration level  
> using iptables or something similar?

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [February 27, 2012, 1:15pm UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/9 "2012-02-27T13:15:17Z")

</div>

You need to set your own firewall rules if you want to restrict connection from specific hosts.

On Monday, February 27, 2012 at 12:41 PM, jajoria abhishek wrote:

> Sir,  
> I can't debarred other systems to connect to my network but I also do not want them to access my elasticserver cluster in any form by specifying the port and server.
> 
> client = new TransportClient().addTransportAddress(new InetSocketTransportAddress(IndexserverName.toString(),port));  
> It is very difficult to configure that on OS network.  
> Is it possible in any from in ES configure level?
> 
> On Mon, Feb 27, 2012 at 2:24 PM, Mark Waddle \<[mark@markwaddle.com](mailto:mark@markwaddle.com) ([mailto:mark@markwaddle.com](mailto:mark@markwaddle.com))\> wrote:
> 
> > Have you considered configuring that at the OS network configuration level using iptables or something similar?

---

<div class="post-metadata">

**Author:** ![Darron\_Froese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/darron_froese/32/2984_2.png) [@Darron\_Froese](https://discuss.elastic.co/u/Darron_Froese)\
**Post date:** [February 27, 2012, 3:57pm UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/10 "2012-02-27T15:57:08Z")

</div>

If you're deploying your Elasticsearch cluster via Chef, it's pretty  
simple to add each IP address to a data bag, then configure the  
firewall on each node from the data bag.

I can post my recipe if anyone's interested.

On Mon, Feb 27, 2012 at 3:41 AM, jajoria abhishek  
[jajoria.abhishek@gmail.com](mailto:jajoria.abhishek@gmail.com) wrote:

> Sir,  
> I can't debarred other systems to connect to my network but I also do not  
> want them to access my elasticserver cluster in any form by specifying the  
> port and server.
> 
> client = new TransportClient().addTransportAddress(new  
> InetSocketTransportAddress(IndexserverName.toString(),port));  
> It is very difficult to configure that on OS network.  
> Is it possible in any from in ES configure level?
> 
> On Mon, Feb 27, 2012 at 2:24 PM, Mark Waddle [mark@markwaddle.com](mailto:mark@markwaddle.com) wrote:
> 
> > Have you considered configuring that at the OS network configuration level  
> > using iptables or something similar?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:38am UTC](https://discuss.elastic.co/t/elasticsearch-server/6778/11 "2017-07-06T03:38:02Z")

</div>


