# Refuse to discovery a new node

**URL:** <https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027>\
**Category:** Elasticsearch\
**Created:** [July 28, 2018, 11:39am UTC](https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027 "2018-07-28T11:39:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Emilia\_N](https://avatars.discourse-cdn.com/v4/letter/e/3e96dc/32.png) [@Emilia\_N](https://discuss.elastic.co/u/Emilia_N)\
**Post date:** [July 28, 2018, 11:39am UTC](https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027/1 "2018-07-28T11:39:23Z")

</div>

Hi

Using `discovery.zen.ping.unicast.hosts: ["host1", "host2"]`, I connect two nodes of Elasticsearch, but I want that the nodes ("host1" and "host2") refuse a new node ("host3") if the node doesn't exist in their list (i.e. "host3" could not join to "host1" and "host2")  
I don't want to use firewall. Is there any config that could help me?

Thank you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 28, 2018, 12:24pm UTC](https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027/2 "2018-07-28T12:24:47Z")

</div>

I think that you need security feature for that (commercial license or trial license needed).

See [https://www.elastic.co/guide/en/elastic-stack-overview/current/ip-filtering.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/ip-filtering.html)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 28, 2018, 12:38pm UTC](https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027/3 "2018-07-28T12:38:46Z")

</div>

One way to prevent other nodes from joining could be to set a random/non-default cluster id. Only nodes with the same cluster id can form a cluster.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 28, 2018, 12:44pm UTC](https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027/4 "2018-07-28T12:44:13Z")

</div>

It would still easy without any auth available to call [http://host1:9200](http://host1:9200) and look what the cluster name is though. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2018, 12:44pm UTC](https://discuss.elastic.co/t/refuse-to-discovery-a-new-node/142027/5 "2018-08-25T12:44:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
