# Restrict access of elasticsearch

**URL:** <https://discuss.elastic.co/t/restrict-access-of-elasticsearch/37287>\
**Category:** Elasticsearch\
**Created:** [December 15, 2015, 10:44pm UTC](https://discuss.elastic.co/t/restrict-access-of-elasticsearch/37287 "2015-12-15T22:44:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DBS](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@DBS](https://discuss.elastic.co/u/DBS)\
**Post date:** [December 15, 2015, 10:44pm UTC](https://discuss.elastic.co/t/restrict-access-of-elasticsearch/37287/1 "2015-12-15T22:44:08Z")

</div>

I built a simple web interface with a search box where users can type quires. However I want to block users from seeing or accessing directly to port 9200 which ES listens to, so no user can retrieve information from ES without going through the interface, nor can modify the index in any way, through the interface or not. Right now when I type localhost:9200 or 127.0.0.1:9200, I can see the entire ES indices ([http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v)). Any suggestion on how to do it? Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 15, 2015, 10:54pm UTC](https://discuss.elastic.co/t/restrict-access-of-elasticsearch/37287/2 "2015-12-15T22:54:12Z")

</div>

You can either proxy it with nginx/apache, or build some restriction stuff into your app.  
Or you can use Shield, which is a commercial plugin we have released.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:30pm UTC](https://discuss.elastic.co/t/restrict-access-of-elasticsearch/37287/3 "2017-07-05T23:30:47Z")

</div>


