# Not able to access vpc based aws elasticsearch domain using proxy server

**URL:** <https://discuss.elastic.co/t/not-able-to-access-vpc-based-aws-elasticsearch-domain-using-proxy-server/192209>\
**Category:** Elasticsearch\
**Created:** [July 25, 2019, 9:28am UTC](https://discuss.elastic.co/t/not-able-to-access-vpc-based-aws-elasticsearch-domain-using-proxy-server/192209 "2019-07-25T09:28:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![a2hksy](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@a2hksy](https://discuss.elastic.co/u/a2hksy)\
**Post date:** [July 25, 2019, 9:28am UTC](https://discuss.elastic.co/t/not-able-to-access-vpc-based-aws-elasticsearch-domain-using-proxy-server/192209/1 "2019-07-25T09:28:49Z")

</div>

Hi,  
I have created a cluster of AWS Elasticsearch service in a VPC. There are many services in my organization that are in different VPC and want to access my Elasticsearch domain.  
To do that a public proxy server can be used and services can communicate with Elasticsearch by using this proxy server.  
So I have created an Nginx server with the domain name "[xyz.example.com](http://xyz.example.com)" that will forward the request to the Elasticsearch.  
And by using the IAM user, I will authorize the Elasticsearch.

I am using this code to connect with Elasticsearch -

```auto
from elasticsearch import Elasticsearch, RequestsHttpConnection
from requests_aws4auth import AWS4Auth

host = 'xyz.example.com'
region = 'ap-southeast-1' # e.g. us-west-1

service = 'es'

awsauth = AWS4Auth(value_of_access_key, value_of_secret_key, region, service)

es = Elasticsearch(
    hosts = [{'host': host, 'port': 443}],
    http_auth = awsauth,
    use_ssl = True,
    verify_certs = True,
    connection_class = RequestsHttpConnection
)

print(es.cluster.health)

So i am getting error -
TransportError(403, u'{"message":"The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details."}')

but when I use native URL of the elastic domain and try to connect from the same vpc. Then I am not getting any error - 

from elasticsearch import Elasticsearch, RequestsHttpConnection
from requests_aws4auth import AWS4Auth

host = 'test-domain.us-east-1.es.amazonaws.com'
region = 'ap-southeast-1' # e.g. us-west-1

service = 'es'

awsauth = AWS4Auth(value_of_access_key, value_of_secret_key, region, service)

es = Elasticsearch(
    hosts = [{'host': host, 'port': 443}],
    http_auth = awsauth,
    use_ssl = True,
    verify_certs = True,
    connection_class = RequestsHttpConnection
)

print(es.cluster.health)

Getting the expected result.
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2019, 9:28am UTC](https://discuss.elastic.co/t/not-able-to-access-vpc-based-aws-elasticsearch-domain-using-proxy-server/192209/2 "2019-08-22T09:28:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
