# How to access elasticsearch as localhost from Nginx server as reverse proxy

**URL:** <https://discuss.elastic.co/t/how-to-access-elasticsearch-as-localhost-from-nginx-server-as-reverse-proxy/175090>\
**Category:** Elasticsearch\
**Created:** [April 3, 2019, 3:00am UTC](https://discuss.elastic.co/t/how-to-access-elasticsearch-as-localhost-from-nginx-server-as-reverse-proxy/175090 "2019-04-03T03:00:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shivawww](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@shivawww](https://discuss.elastic.co/u/shivawww)\
**Post date:** [April 3, 2019, 3:00am UTC](https://discuss.elastic.co/t/how-to-access-elasticsearch-as-localhost-from-nginx-server-as-reverse-proxy/175090/1 "2019-04-03T03:00:18Z")

</div>

How to access as localhost from Nginx server as reverse proxy  
I have 4 elasticsearch node on 4 separate servers:  
xx.xxx.1.20  
xx.xxx.1.21  
xx.xxx.1.22  
xx.xxx.1.23

Nginx is running on separate server:  
xx.xxx.6.14

In elasticsearch.yml on each of the above elasticsearch nodes  
http.host: 127.0.0.1  
http.port: 9200

I want to access elasticsearch through NGINX as reverse proxy server as [http://xx.xxx.6.14:9211](http://xx.xxx.6.14:9211)

Going by the [Elasticsearch Ip restriction using NGINX](https://discuss.elastic.co/t/elasticsearch-ip-restriction-using-nginx/91145)  
I tried with iptables to restrict elasticsearch access through only NGINX as below on each of the easticsearch nodes

iptables -A INPUT -p tcp --dport 9200 -s xx.xxx.6.14 -j ACCEPT  
iptables -A INPUT -p tcp --dport 9200 -j DROP

It is not working. I am unable access elasticsearch as [http://127.0.0.1:9200](http://127.0.0.1:9200) from nginx server

Can nobody please help me here.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 3, 2019, 7:53am UTC](https://discuss.elastic.co/t/how-to-access-elasticsearch-as-localhost-from-nginx-server-as-reverse-proxy/175090/2 "2019-04-03T07:53:30Z")

</div>

if you bind to localhost/127.0.0.1, nginx will not be able to reach elasticsearch over the network.

---

<div class="post-metadata">

**Author:** ![shivawww](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@shivawww](https://discuss.elastic.co/u/shivawww)\
**Post date:** [April 4, 2019, 3:41am UTC](https://discuss.elastic.co/t/how-to-access-elasticsearch-as-localhost-from-nginx-server-as-reverse-proxy/175090/3 "2019-04-04T03:41:59Z")

</div>

My idea of having Nginx in front of elastisearch is to protect elasticsearch. I want to restrict direct access of elasticsearch from data/and master nodes without any authorization.  
In Nginx config file I am applying Authentication for Elasticsearch.

upstream elasticsearch {  
server 127.0.0.1:9200;  
server 127.0.0.1:9201;  
server 127.0.0.1:9202;  
server 127.0.0.1:9203;  
keepalive 15;  
}  
server {  
listen 8050;  
server\_name xx.xxx.6.14;  
auth\_basic "Protected Elasticsearch";  
auth\_basic\_user\_file /u11/nginx/config/conf.d/elasticsearch.htpasswd;

```
  location / {
  proxy_pass http://elasticsearch;
  proxy_set_header Connection "Keep-Alive";
  proxy_set_header Proxy-Connection "Keep-Alive";
  proxy_redirect off;
}

```

}

What action is to be taken in network to proxy\_pass from nginx to remote elastic server where in the remote server elasticsearch runs as localhost

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2019, 3:42am UTC](https://discuss.elastic.co/t/how-to-access-elasticsearch-as-localhost-from-nginx-server-as-reverse-proxy/175090/4 "2019-05-02T03:42:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
