# Filebeat Firewall requirements

**URL:** https://discuss.elastic.co/t/filebeat-firewall-requirements/38399
**Category:** Beats
**Tags:** filebeat
**Created:** [January 5, 2016, 12:09pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399 "2016-01-05T12:09:25Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)
#### Post date: [January 5, 2016, 12:09pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/1 "2016-01-05T12:09:25Z")

</div>

Hi, community.

I have:

- 1 host with application which writes logs in the file and filebeat reads it and send to logstash
- logstash cluster of 3 nodes

Firewall rules are opened only as follows:  
filebeat (port number 5403) -\> (5403) logstash

When I start filebeat it tells me:  
`2016-01-02T06:59:18-05:00 DBG Try to publish %!s(int=1024) events to logstash with window size %!s(int=10) 2016-01-02T06:59:18-05:00 DBG %!s(int=0) events out of %!s(int=1024) events sent to logstash. Continue sending ... 2016-01-02T06:59:18-05:00 INFO Error publishing events (retrying): read tcp filebeat:47021->logstash_host:5403: read: connection reset by peer 2016-01-02T06:59:18-05:00 DBG Try to publish %!s(int=1024) events to logstash with window size %!s(int=10) 2016-01-02T06:59:18-05:00 DBG %!s(int=0) events out of %!s(int=1024) events sent to logstash. Continue sending ... 2016-01-02T06:59:18-05:00 INFO Error publishing events (retrying): read tcp filebeat:47022->logstash_host:5403: read: connection reset by peer`

So the question is why filebeat sends each 1024 events using another port number?  
In my example they are 47021, 47022...  
Why it is not 5403?  
I can configure my Firewall rules only for port 5403.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 5, 2016, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/2 "2016-01-05T13:54:03Z")

</div>

> So the question is why filebeat sends each 1024 events using another port number?  
> In my example they are 47021, 47022...

That's the randomly picked local port used by Filebeat. A TCP connection is defined by two (IP, port) endpoints, in your case e.g. (filebeat, 47022) and (logstash\_host, 5403). While it's technically possible to pick a particular local port when opening a connection it's quite unusual and Filebeat doesn't support it.

Filebeat is able to make the connection to Logstash (or whatever is listening), so that's good. What's your Logstash configuration?

---

<div class="post-metadata">

### Author: ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)
#### Post date: [January 5, 2016, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/3 "2016-01-05T13:59:34Z")

</div>

> [@magnusbaeck](#):
>
> While it's technically possible to pick a particular local port when opening a connection it's quite unusual and Filebeat doesn't support it.

So what is the solution for Production systems?  
Should I open all the ports starting with number 1024 on Production?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 5, 2016, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/4 "2016-01-05T14:04:10Z")

</div>

Firewalls are typically configured to allow any _source port_ (the Filebeat end in this case) because, as I said, source ports are randomly picked from the full range of port numbers. Firewall restrictions are instead placed on the _destination port_ (5403 in your case).

---

<div class="post-metadata">

### Author: ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)
#### Post date: [January 5, 2016, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/5 "2016-01-05T14:27:16Z")

</div>

> [@magnusbaeck](#):
>
> the full range of port numbers

Could you please advise which range exactly you mentioned? In numbers I mean.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 5, 2016, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/6 "2016-01-05T14:31:55Z")

</div>

> **[Transmission Control Protocol | TCP ports](https://en.wikipedia.org/wiki/Transmission_Control_Protocol#TCP_ports)**
>
> TCP and UDP use port numbers to identify sending and receiving application end-points on a host, often called Internet sockets. Each side of a TCP connection has an associated 16-bit unsigned port number (0-65535) reserved by the sending or receiving application. Arriving TCP packets are identified as belonging to a specific TCP connection by its sockets, that is, the combination of source host address, source port, destination host address, and destination port. This means that a server computer...

---

<div class="post-metadata">

### Author: ![bibikmik](https://avatars.discourse-cdn.com/v4/letter/b/898d66/32.png) [@bibikmik](https://discuss.elastic.co/u/bibikmik)
#### Post date: [January 11, 2016, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/7 "2016-01-11T12:45:29Z")

</div>

For those who faced the same issue.  
I've got official response from Elastic support as follows:

> Source port selection is a function of the underlying operating system, and generally an application has no control over this. [See here for details](https://www.cymru.com/jtk/misc/ephemeralports.html).  
> For example, Linux systems will choose a random source port between **32768 - 61000**.

It was advised to use [Stateful Firewall](https://en.wikipedia.org/wiki/Stateful_firewall).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:56pm UTC](https://discuss.elastic.co/t/filebeat-firewall-requirements/38399/8 "2017-07-05T21:56:53Z")

</div>


