# Filebeat clients specified by ip addresses for 'force\_peer'

**URL:** <https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 26, 2018, 12:38pm UTC](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009 "2018-09-26T12:38:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![peter\_j](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@peter\_j](https://discuss.elastic.co/u/peter_j)\
**Post date:** [September 26, 2018, 12:38pm UTC](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009/1 "2018-09-26T12:38:34Z")

</div>

Hello  
I'm authenticating FileBeat clients on Logstash over ssl (ssl\_verify\_mode: force\_peer).

I created self signed cert

```auto
../bin/elasticsearch-certutil ca --pem --silent --out ca.zip

```

then generated logstash and filebeat certs

```auto
elasticsearch-certutil cert --silent --pem --in instances.yml --ca-cert ca/ca.crt --ca-key ca/ca.key --out cert.zip

```

I created instances.yml und run elasticsearch-certutil with elasticsearch-certutil --in instances.yml ...

It works but the FileBeat clients are specified in instances.yml by their ip addresses.

```auto
  - name: logstash_unit1
    dns:
      - logstash
      - node1
      - localhost
  - name: filebeat
    dns:
      - node1
      - node2
      - localhost
    ip:
      - 161.222.72.115
      - 127.0.0.1

```

The FileBeat clients connects to logstash over proxy and their ip addresses can change.  
Can i specify an address range instead of ip address?  
How can i get rid of ip addresses for filebeat client certs?

Thank you  
Peter

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 27, 2018, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009/2 "2018-09-27T15:06:23Z")

</div>

Could you try to just remove the IP addresses and rely only the dns names?

---

<div class="post-metadata">

**Author:** ![peter\_j](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@peter\_j](https://discuss.elastic.co/u/peter_j)\
**Post date:** [September 28, 2018, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009/3 "2018-09-28T14:27:25Z")

</div>

Removed the ips and it works. Seems like ssl client-auth doesn't need the ips.

BTW Elastic is awesome 😉  
Peter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 26, 2018, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009/4 "2018-10-26T14:27:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
