# Ip-filtering

**URL:** <https://discuss.elastic.co/t/ip-filtering/128328>\
**Category:** Elasticsearch\
**Created:** [April 17, 2018, 9:37am UTC](https://discuss.elastic.co/t/ip-filtering/128328 "2018-04-17T09:37:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)\
**Post date:** [April 17, 2018, 9:37am UTC](https://discuss.elastic.co/t/ip-filtering/128328/1 "2018-04-17T09:37:29Z")

</div>

Hello,

I want to migrate from configuration property ip-filtering to dynamic:  
[https://www.elastic.co/guide/en/x-pack/current/ip-filtering.html#dynamic-ip-filtering](https://www.elastic.co/guide/en/x-pack/current/ip-filtering.html#dynamic-ip-filtering)

If I want to add a host, or remove a host can I do it host by host?  
what happens with the statically configured IPs? are they merged with the dynamic ones or lost?

regards

---

<div class="post-metadata">

**Author:** ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)\
**Post date:** [April 20, 2018, 4:11pm UTC](https://discuss.elastic.co/t/ip-filtering/128328/2 "2018-04-20T16:11:45Z")

</div>

HHEEELLLP !!!! SOS !!!

I tried (replace the xxx)

```auto
PUT /_cluster/settings
{
    "persistent" : {
        "xpack.security.transport.filter.allow" : "88.xxx.xxx.83"
    }
}

```

and now I cannot connect my cluster! even in localhost!

```auto
curl -u elastic:password "http://localhost:9200/_cluster/settings"
curl: (56) Recv failure: Connection reset by peer

```

How can I recover????

PS: I had

```auto
        xpack.security.transport.filter.allow: ['some IPs']
        xpack.security.transport.filter.deny: _all

```

---

<div class="post-metadata">

**Author:** ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)\
**Post date:** [April 20, 2018, 6:46pm UTC](https://discuss.elastic.co/t/ip-filtering/128328/3 "2018-04-20T18:46:13Z")

</div>

Here is some interesting stack trace:

```auto

[2018-04-20T18:02:11,967][WARN][o.e.g.DanglingIndicesState] [wilco-2] [[.monitoring-es-6-2018.04.16/IuLNNiMKTCyaZWkxYshq6w]] can not be imported as a dangling index, as index with same name already exists in cluster metadata
[2018-04-20T18:02:11,967][INFO][o.e.c.m.TemplateUpgradeService] [wilco-2] Finished upgrading templates to version 6.2.2
[2018-04-20T18:02:17,283][ERROR][o.e.x.w.t.s.ExecutableScriptTransform] [wilco-2] failed to execute [script] transform for [UTIZbUvoTtizEv91Q260jQ_elasticsearch_cluster_status_b8610155-8b8a-4c78-8125-1b90dac5f1fe-2018-04-20T16:02:17.258Z]
org.elasticsearch.script.ScriptException: runtime error
	at org.elasticsearch.painless.PainlessScript.convertToScriptException(PainlessScript.java:101) ~[?:?]
	at org.elasticsearch.painless.PainlessScript$Script.execute(ctx.vars.email_recipient = (ctx.payload.kibana_settings.hits.total > 0) ? ctx.payload.kibana_settings.hits.hits[0]._source.kibana_settings.xpack.default_admin_email : null;ctx.vars.is_new = ctx.vars.fails_check && !ctx.vars.not_resolved;ctx.vars.is_resolve ...:1070) ~[?:?]
	at org.elasticsearch.painless.ScriptImpl.run(ScriptImpl.java:105) ~[?:?]
	at org.elasticsearch.xpack.watcher.transform.script.ExecutableScriptTransform.doExecute(ExecutableScriptTransform.java:69) ~[x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.xpack.watcher.transform.script.ExecutableScriptTransform.execute(ExecutableScriptTransform.java:53) ~[x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.xpack.watcher.transform.script.ExecutableScriptTransform.execute(ExecutableScriptTransform.java:38) ~[x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.xpack.watcher.execution.ExecutionService.executeInner(ExecutionService.java:481) ~[x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.xpack.watcher.execution.ExecutionService.execute(ExecutionService.java:322) ~[x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.xpack.watcher.execution.ExecutionService.lambda$executeAsync$7(ExecutionService.java:426) ~[x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.xpack.watcher.execution.ExecutionService$WatchExecutionTask.run(ExecutionService.java:580) [x-pack-watcher-6.2.2.jar:6.2.2]
	at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:573) [elasticsearch-6.2.2.jar:6.2.2]
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) [?:1.8.0_121]
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617) [?:1.8.0_121]
	at java.lang.Thread.run(Thread.java:745) [?:1.8.0_121]
Caused by: java.lang.IndexOutOfBoundsException: Index: 0, Size: 0
	at java.util.ArrayList.rangeCheck(ArrayList.java:653) ~[?:1.8.0_121]
	at java.util.ArrayList.get(ArrayList.java:429) ~[?:1.8.0_121]
	at org.elasticsearch.painless.PainlessScript$Script.execute(ctx.vars.email_recipient = (ctx.payload.kibana_settings.hits.total > 0) ? ctx.payload.kibana_settings.hits.hits[0]._source.kibana_settings.xpack.default_admin_email : null;ctx.vars.is_new = ctx.vars.fails_check && !ctx.vars.not_resolved;ctx.vars.is_resolve ...:347) ~[?:?]
	... 12 more

```

---

<div class="post-metadata">

**Author:** ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)\
**Post date:** [April 20, 2018, 7:44pm UTC](https://discuss.elastic.co/t/ip-filtering/128328/4 "2018-04-20T19:44:21Z")

</div>

Still stucked. I have restarted my cluster, after adding `xpack.security.transport.filter.enabled: false` on each node, but the result is the same. Cannot connect the cluster. But I know the server is GREEN because I did receive an email from x-pack monitoring

```auto
root@wilco-1:~# nc -z -v -w5 localhost 9200
localhost [127.0.0.1] 9200 (?) open
root@wilco-1:~# curl -u elastic:3s3rqT102v0yZF0kHGdG http://localhost:9200
curl: (56) Recv failure: Connection reset by peer
```

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [April 22, 2018, 2:06pm UTC](https://discuss.elastic.co/t/ip-filtering/128328/5 "2018-04-22T14:06:55Z")

</div>

Hey dao,

Hope you and your cluster are well.

> [@dao](#):
>
> If I want to add a host, or remove a host can I do it host by host?
> 
> what happens with the statically configured IPs? are they merged with the dynamic ones or lost?

The ip filtering rules work just like any other cluster setting, see [precedence of settings](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-update-settings.html#_precedence_of_settings) . You cannot mix conf file settings with the dynamic ones or append them, you only set or unset them, in file or via the api where the api has precedence.

I have not fully acknowledged the fail state you are describing.

> ```
> xpack.security.transport.filter.allow: ['some IPs']
> xpack.security.transport.filter.deny: _all
> 
> ```

This should not gate the HTTP layer, curl should work. Also, turning `xpack.security.transport.filter.enabled: false` should disable filtering. All this assumes that only the settings mentioned previously have been set via the API. Otherwise, any other settings applied from the API take precedence.

In all case, have you tried to temporarily set the public IP "88.xxx.xxx.83" on the local network interface of one of the nodes, run the curl which clears all the settings, then revert the dummy IP addr ?

---

<div class="post-metadata">

**Author:** ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)\
**Post date:** [April 22, 2018, 9:34pm UTC](https://discuss.elastic.co/t/ip-filtering/128328/6 "2018-04-22T21:34:32Z")

</div>

Hello Albert,

I am better compared to the friday-PM-last-minute-change that ruined my apero

Anyway, I did exactly what you have suggested and saved the accesses. I have decided to disable IP-Filtering and set it up with a standard linux firewall (UFW). I feel better this way because I always can ssh the server to be behind the firewall.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2018, 9:34pm UTC](https://discuss.elastic.co/t/ip-filtering/128328/7 "2018-05-20T21:34:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
