# Network config for cluster behind proxy - clarifying documentation

**URL:** <https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799>\
**Category:** Elasticsearch\
**Created:** [May 11, 2016, 3:54pm UTC](https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799 "2016-05-11T15:54:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fran\_Fabrizio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_fabrizio/32/9533_2.png) [@Fran\_Fabrizio](https://discuss.elastic.co/u/Fran_Fabrizio)\
**Post date:** [May 11, 2016, 3:54pm UTC](https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799/1 "2016-05-11T15:54:20Z")

</div>

I just spent an hour going down the wrong rabbit hole because of some misleading documentation, so I thought I'd post this here in hopes of helping others.

If you have multiple nodes, and you're trying to put your cluster behind a proxy, these are probably the network settings you want:

```
network.host: _local_
transport.host: _eth0_ #or wherever all the nodes can see each other

```

This will give you the desired effect of having 9200/9300 only accessible from localhost while still allowing nodes to find and talk to each other.

The docs led me to believe that network.bind\_host and network.publish\_host were the way to accomplish this. [The docs state](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html): "The network.host setting explained in Commonly used network settings is a shortcut which sets the bind host and the publish host at the same time. In advanced used cases, such as when running behind a proxy server, you may need to set these settings to different values"

The reality is that **Elasticsearch will only bind to the interfaces set in network.bind\_host no matter what you set network.publish\_host to**. I was trying a bind\_host of _local_ and publish\_host of _eth0_, but I could see that ES was still only listening on the local interface.

I hope this saves someone some time someday. In my Googling, I found others confused about the same issue but no great explanation of the right way. Maybe the docs could clarify this. I haven't figured out the use case where splitting bind\_host and publish\_host is useful, but apparently not for a typical proxy setup. 🙂 (I could be missing something, if so, someone please set me straight!)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 12, 2016, 12:40am UTC](https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799/2 "2016-05-12T00:40:34Z")

</div>

> [@Fran\_Fabrizio](#):
>
> The reality is that Elasticsearch will only bind to the interfaces set in network.bind\_host no matter what you set network.publish\_host to. I was trying a bind\_host of local and publish\_host of eth0, but I could see that ES was still only listening on the local interface.

That shouldn't happen. What version are you on?

---

<div class="post-metadata">

**Author:** ![Fran\_Fabrizio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_fabrizio/32/9533_2.png) [@Fran\_Fabrizio](https://discuss.elastic.co/u/Fran_Fabrizio)\
**Post date:** [May 12, 2016, 2:13am UTC](https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799/3 "2016-05-12T02:13:14Z")

</div>

Version 2.3.2.

But I'm pretty sure that is what should happen, now that I understand the settings better. Clinton Gormley explains it here: [https://github.com/elastic/elasticsearch/issues/10015](https://github.com/elastic/elasticsearch/issues/10015)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 12, 2016, 2:14am UTC](https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799/4 "2016-05-12T02:14:22Z")

</div>

Ahh ok, that makes sense 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:52pm UTC](https://discuss.elastic.co/t/network-config-for-cluster-behind-proxy-clarifying-documentation/49799/5 "2017-07-05T22:52:17Z")

</div>


