# How make our Elastic cluster is secure for replica creation from outside cluster machines?

**URL:** <https://discuss.elastic.co/t/how-make-our-elastic-cluster-is-secure-for-replica-creation-from-outside-cluster-machines/147048>\
**Category:** Elasticsearch\
**Created:** [September 3, 2018, 10:32am UTC](https://discuss.elastic.co/t/how-make-our-elastic-cluster-is-secure-for-replica-creation-from-outside-cluster-machines/147048 "2018-09-03T10:32:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [September 3, 2018, 10:32am UTC](https://discuss.elastic.co/t/how-make-our-elastic-cluster-is-secure-for-replica-creation-from-outside-cluster-machines/147048/1 "2018-09-03T10:32:26Z")

</div>

I have an Elasticsearch cluster (6.4.0) with one Master node and one data node .  
Xpack is enabled in both machines. Both machines are working well .

Indexes are available in both machines

user:elastic and p/w: changeme in both machines.

Master node: (IP : 192.168.1.1)  
node.master: true  
node.data: false  
discovery.zen.ping.unicast.hosts: ["192.168.1.2"]

Data Node: (IP: 192.168.1.2)  
node.master: false  
node.data: true  
discovery.zen.ping.unicast.hosts: ["192.168.1.1"]

My Question is ,

" discovery.zen.ping.unicast.hosts" is the only one option for for restrict index creation from any out side machines to our cluster ?

Is there any other security mechanism for restrict index/replica creation from a non cluster ES machine in our cluster ?

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [September 4, 2018, 5:39pm UTC](https://discuss.elastic.co/t/how-make-our-elastic-cluster-is-secure-for-replica-creation-from-outside-cluster-machines/147048/2 "2018-09-04T17:39:32Z")

</div>

> Is there any other security mechanism for restrict index/replica creation from a non cluster ES machine in our cluster ?

I understand that you are concerned about unknown nodes joining the cluster.

Node discovery and cluster formation is done through the transport network module.  
Enabling Security allows you to enable authentication on the transport layer as part of configuring [TLS](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html#tls-transport).  
In this case, only nodes that poses certificates (for their hosts) will be able to join the cluster.

Without TLS on the transport layer, you are right the cluster is vulnerable to being hijacked, unless there are other OS level (firewall) provisions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2018, 5:50pm UTC](https://discuss.elastic.co/t/how-make-our-elastic-cluster-is-secure-for-replica-creation-from-outside-cluster-machines/147048/3 "2018-10-02T17:50:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
