# Limiting REST API commands to localhost with 2 node cluster

**URL:** <https://discuss.elastic.co/t/limiting-rest-api-commands-to-localhost-with-2-node-cluster/22604>\
**Category:** Elasticsearch\
**Created:** [March 10, 2015, 7:01pm UTC](https://discuss.elastic.co/t/limiting-rest-api-commands-to-localhost-with-2-node-cluster/22604 "2015-03-10T19:01:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Scott\_3](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Scott\_3](https://discuss.elastic.co/u/Scott_3)\
**Post date:** [March 10, 2015, 7:01pm UTC](https://discuss.elastic.co/t/limiting-rest-api-commands-to-localhost-with-2-node-cluster/22604/1 "2015-03-10T19:01:16Z")

</div>

Hello, in the interest of security I had read that it was best to limit  
being able to query elasticsearch directly to localhost, and only allow  
users to search elasticsearch using Kibana. This has worked fine by  
setting the network.bind\_host to localhost, but when I go to add another  
node to the cluster I get connection refused errors? Does anybody know  
what I am doing wrong?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 11, 2015, 12:54am UTC](https://discuss.elastic.co/t/limiting-rest-api-commands-to-localhost-with-2-node-cluster/22604/2 "2015-03-11T00:54:46Z")

</div>

See

> **[Networking | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html)**

The bind\_host setting controls what network interface Elasticsearch listens  
on, which is useful if you have multiple NICs. publish\_host setting  
controls what IP address Elasticsearch uses to talk to other nodes in the  
cluster.

If you want to only query via localhost then set bind\_host to loopback and  
publish\_host to the other interface (eg eth0).

On 10 March 2015 at 12:01, Scott [sunglee2@gmail.com](mailto:sunglee2@gmail.com) wrote:

> Hello, in the interest of security I had read that it was best to limit  
> being able to query elasticsearch directly to localhost, and only allow  
> users to search elasticsearch using Kibana. This has worked fine by  
> setting the network.bind\_host to localhost, but when I go to add another  
> node to the cluster I get connection refused errors? Does anybody know  
> what I am doing wrong?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X9U%2BMZagzzZCbAP66onfJePGGH2r3\_0i2%2BgADFrJ8tTxA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X9U%2BMZagzzZCbAP66onfJePGGH2r3_0i2%2BgADFrJ8tTxA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Scott\_3](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Scott\_3](https://discuss.elastic.co/u/Scott_3)\
**Post date:** [March 11, 2015, 1:15pm UTC](https://discuss.elastic.co/t/limiting-rest-api-commands-to-localhost-with-2-node-cluster/22604/3 "2015-03-11T13:15:36Z")

</div>

Thanks Mark, that was my understanding as well. However, when I do that,  
the second node can't join the cluster. It will only work when I set the  
bind\_host to 0.0.0.0. Setting it to 127.0.0.1 does indeed limit the  
queries to localhost, but then when I try and add a second node to the  
cluster ES just spits out connection refused errors. I thought the  
publish\_host was the interface that ES uses to communicate with other nodes?

On Tuesday, March 10, 2015 at 8:55:12 PM UTC-4, Mark Walkom wrote:

> See  
> [Networking | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html)
> 
> The bind\_host setting controls what network interface Elasticsearch  
> listens on, which is useful if you have multiple NICs. publish\_host setting  
> controls what IP address Elasticsearch uses to talk to other nodes in the  
> cluster.
> 
> If you want to only query via localhost then set bind\_host to loopback and  
> publish\_host to the other interface (eg eth0).
> 
> On 10 March 2015 at 12:01, Scott \<[sung...@gmail.com](mailto:sung...@gmail.com) \<javascript:\>\> wrote:
> 
> > Hello, in the interest of security I had read that it was best to limit  
> > being able to query elasticsearch directly to localhost, and only allow  
> > users to search elasticsearch using Kibana. This has worked fine by  
> > setting the network.bind\_host to localhost, but when I go to add another  
> > node to the cluster I get connection refused errors? Does anybody know  
> > what I am doing wrong?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ee71a5f2-35dd-4d03-9495-0ed7a7db2afd%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/88311c12-3b5a-498a-b219-e514bb73171d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/88311c12-3b5a-498a-b219-e514bb73171d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:27am UTC](https://discuss.elastic.co/t/limiting-rest-api-commands-to-localhost-with-2-node-cluster/22604/4 "2017-07-06T00:27:26Z")

</div>


