# Questions regardings ports and network flows

**URL:** <https://discuss.elastic.co/t/questions-regardings-ports-and-network-flows/251440>\
**Category:** Elasticsearch\
**Created:** [October 8, 2020, 12:58pm UTC](https://discuss.elastic.co/t/questions-regardings-ports-and-network-flows/251440 "2020-10-08T12:58:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juicy45](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juicy45/32/77526_2.png) [@Juicy45](https://discuss.elastic.co/u/Juicy45)\
**Post date:** [October 8, 2020, 12:58pm UTC](https://discuss.elastic.co/t/questions-regardings-ports-and-network-flows/251440/1 "2020-10-08T12:58:02Z")

</div>

Hi,

I have some questions regardings the network flows and ports. I already know that elasticsearch is using 9200 and 9300 ports.

- 9200 for the requests
- 9300 for the communication between nodes

1. Which port is using elasticsearch for transferring data between nodes (example : hot to warm)
2. Do we need to open the 9200 port between the nodes or it's only for the client's requests ?
3. Do we need to open in two-way the 9300 ports on all nodes on the firewall ?

Thank you for your answers

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 8, 2020, 2:15pm UTC](https://discuss.elastic.co/t/questions-regardings-ports-and-network-flows/251440/2 "2020-10-08T14:15:22Z")

</div>

1. 9300
2. No. Not needed.
3. Yes. The communication between nodes can be in all ways.

Normally the nodes are located in the same network, like you'd put your databases. So I'd definitely "protect" the whole network where Elasticsearch is running. Not sure I'd "protect" each machine individually but I'm not a network expert 🙂

I'd say that inside the network: open 9300 (and why not 9200). From the outside, only open 9200.  
Hoe this makes sense.

---

<div class="post-metadata">

**Author:** ![Juicy45](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juicy45/32/77526_2.png) [@Juicy45](https://discuss.elastic.co/u/Juicy45)\
**Post date:** [October 9, 2020, 1:58pm UTC](https://discuss.elastic.co/t/questions-regardings-ports-and-network-flows/251440/3 "2020-10-09T13:58:48Z")

</div>

> [@dadoonet](#):
>
> are located in the same network, like you'd put your databases. So I'd definitely "protect" the whole network where Elasticsearch is running. Not sure I'd "protect" each machine individually but I'm not a network expert 🙂

Hi David,

Thank you for your answer. I place your answer as the solution.

Unfortunately, I have to open connection on each machine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2020, 1:59pm UTC](https://discuss.elastic.co/t/questions-regardings-ports-and-network-flows/251440/4 "2020-11-06T13:59:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
