# Remote cluster - TCP connection is not happened with Istio ingress

**URL:** <https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [April 23, 2021, 5:59am UTC](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040 "2021-04-23T05:59:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmssath](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@rmssath](https://discuss.elastic.co/u/rmssath)\
**Post date:** [April 23, 2021, 5:59am UTC](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040/1 "2021-04-23T05:59:30Z")

</div>

Hi Team,

We have followed the below step to configure remote cluster.

> **[Remote clusters | Elastic Cloud on Kubernetes \[1.5\] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-remote-clusters.html)**

In remote cluster, we have create istio ingress gateway/virtualservice with TCP to expose the service.

```auto
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: es-gateway
spec:
  selector:
    istio: ingressgateway # use Istio default gateway implementation
  servers:
  - port:
      number: 9500
      name: hello1
      protocol: TCP
    hosts:
    - "*"
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: es-vs
spec:
  hosts:
  - "*"
  gateways:
  - es-gateway
  tcp:
  - match:
    - port: 9500
    route:
    - destination:
        port:
          number: 9300
        host: quickstart-es-transport.default.svc.cluster.local

```

After configure remote cluster, we are getting request in remote cluster (istio logs) like below which is failed to connect.

Note: x.x.x.x is remote cluster

```auto
[2021-04-22T13:02:59.554Z] "- - -" 0 UH "-" "-" 0 0 0 - "-" "-" "-" "-" "-" - - x.x.x.x:9500 y.y.y.y:46395 - -
[2021-04-22T13:02:59.554Z] "- - -" 0 UH "-" "-" 0 0 0 - "-" "-" "-" "-" "-" - - x.x.x.x:9500 y.y.y.y:29463 - -
[2021-04-22T13:02:59.554Z] "- - -" 0 UH "-" "-" 0 0 0 - "-" "-" "-" "-" "-" - - x.x.x.x:9500 y.y.y.y:9801 - -
[2021-04-22T13:02:59.554Z] "- - -" 0 UH "-" "-" 0 0 0 - "-" "-" "-" "-" "-" - - x.x.x.x:9500 y.y.y.y:53429 - -
[2021-04-22T13:02:59.554Z] "- - -" 0 UH "-" "-" 0 0 0 - "-" "-" "-" "-" "-" - - x.x.x.x:9500 y.y.y.y:35396 - -

```

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [April 28, 2021, 4:27pm UTC](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040/2 "2021-04-28T16:27:00Z")

</div>

Hello,

I wonder if the issue comes from the remote cluster setup or the Istio setup. Could you first try without Istio to better isolate the problem?

---

<div class="post-metadata">

**Author:** ![rmssath](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@rmssath](https://discuss.elastic.co/u/rmssath)\
**Post date:** [May 4, 2021, 6:47am UTC](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040/3 "2021-05-04T06:47:40Z")

</div>

Thanks Richard..

We are able to access the remote cluster with nodeport. Above issue is occur only on configuring with istio.

Is any changes or additional config required in above virtualservice?

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [May 4, 2021, 8:57am UTC](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040/4 "2021-05-04T08:57:01Z")

</div>

You have to exclude the transport port (port 9300) from being proxied. Currently ECK does not support switching off X-Pack security and TLS for the Elasticsearch transport port. If Istio is allowed to proxy the transport port, the traffic is encrypted twice and communication between Elasticsearch nodes is disrupted.

See the documentation: [Istio | Elastic Cloud on Kubernetes [1.5] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-service-mesh-istio.html).  
Check the [recipes directory](https://github.com/elastic/cloud-on-k8s/tree/1.5/config/recipes) in the ECK source repository for a complete example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2021, 8:57am UTC](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040/5 "2021-06-01T08:57:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
