# Kibana4 behind Apache2 Proxy

**URL:** <https://discuss.elastic.co/t/kibana4-behind-apache2-proxy/62305>\
**Category:** Kibana\
**Created:** [October 5, 2016, 5:41pm UTC](https://discuss.elastic.co/t/kibana4-behind-apache2-proxy/62305 "2016-10-05T17:41:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_Hargraves](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_hargraves/32/12313_2.png) [@Chris\_Hargraves](https://discuss.elastic.co/u/Chris_Hargraves)\
**Post date:** [October 5, 2016, 5:41pm UTC](https://discuss.elastic.co/t/kibana4-behind-apache2-proxy/62305/1 "2016-10-05T17:41:05Z")

</div>

I decided to use Apache as a reverse proxy based on some Googling and I am having an issue. I can get the proxy to work when I just put in [http://logserver.host.com/](http://logserver.host.com/) and it asks me for the credentials I set up. However, when I put in the Kibana port, I can get to Kibana around apache. So [http://logserver.host.com:5601](http://logserver.host.com:5601) will bypass the authentication I set up.

```
<VirtualHost *:80>
        ServerName loggingserver
        ServerAdmin admin@admin.com

  #
  # Proxy
  #
  ProxyRequests Off
  <Proxy *>
    Order Allow,Deny
    Allow from all
    AuthType Basic
    AuthName "Halt! This is a restricted area. Please provide credentials."
    AuthUserFile /path/to/file.htpwd
    Require valid-user
  </Proxy>
  ProxyRequests Off
  ProxyPass / http://127.0.0.1:5601
  ProxyPassReverse / http://127.0.0.1:5601
  RewriteEngine on
  RewriteCond %{DOCUMENT_ROOT}/%{REQUEST_FILENAME} !-f
  RewriteRule .* http://127.0.0.1:5601%{REQUEST_URI} [P,QSA]

        ErrorLog ${APACHE_LOG_DIR}/kibana_error.log
        LogLevel warn
        CustomLog ${APACHE_LOG_DIR}/kibana_access.log combined
</VirtualHost>

```

I tried to add a basepath to the kibana.yml config file but that strangely just adds extra paths to the url, which of course doesn't work at all.

Any ideas?

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [October 5, 2016, 6:31pm UTC](https://discuss.elastic.co/t/kibana4-behind-apache2-proxy/62305/2 "2016-10-05T18:31:20Z")

</div>

You will need to add firewall rules to prevent access to the port directly.

---

<div class="post-metadata">

**Author:** ![Chris\_Hargraves](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_hargraves/32/12313_2.png) [@Chris\_Hargraves](https://discuss.elastic.co/u/Chris_Hargraves)\
**Post date:** [October 5, 2016, 8:42pm UTC](https://discuss.elastic.co/t/kibana4-behind-apache2-proxy/62305/3 "2016-10-05T20:42:11Z")

</div>

Well then, that was easy. Thank you so much. Everything works as intended and I'm ready to start filling it up with clients and custom visualizations.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:37pm UTC](https://discuss.elastic.co/t/kibana4-behind-apache2-proxy/62305/4 "2017-07-06T13:37:30Z")

</div>


