# Restrict communication to elsticsearch cluster using searchguard

**URL:** <https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317>\
**Category:** Elasticsearch\
**Created:** [June 21, 2017, 3:01pm UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317 "2017-06-21T15:01:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [June 21, 2017, 3:01pm UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/1 "2017-06-21T15:01:40Z")

</div>

Hi

I would like to restrict elasticsearch cluster communication to certain IPs using searchguard plugin.

I have researched alot on this and could not find a solution for this.

I found that it is possible with Shield and X-pack plugins, but my goal is to achieve this with searchguard.

Please help me to find a solution for this.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkressin/32/17765_2.png) [@jkressin](https://discuss.elastic.co/u/jkressin)\
**Post date:** [June 22, 2017, 9:09am UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/2 "2017-06-22T09:09:15Z")

</div>

_Disclaimer: I work for [floragunn](https://floragunn.com/), the makers of Search Guard._

Search Guard has a different approach for that requirement. We use TLS certificates to control which machines can connect to your cluster. TLS is mandatory on the transport layer and cannot be switched off. So only machines with a valid certificate signed by your Root CA are allowed to join. This offers a more flexible solution since you can add machines without having to re-configure Elasticsearch/Search Guard. In addition, you can configure Search Guard to verify the hostnames in the certificates, and you can check the hostnames against your DNS. By using intermediate certificates, it's also easy to revoke certificates if necessary. We believe this offers a better and more flexible approach than to just use IP restrictions.

You can read more about the Search Guard TLS configuration in the official [documentation](http://floragunncom.github.io/search-guard-docs/tls_configuration.html).

For client/REST communication, you can also use hostname verification to control access.

There's also our [Search Guard Google Group](https://groups.google.com/forum/#!forum/search-guard) for any Search Guard specific questions.

---

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [June 22, 2017, 10:14am UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/3 "2017-06-22T10:14:36Z")

</div>

I want to connect to elasticsearch cluster from other IPs that were not configured for cluster, that means:

I have a 3 node cluster with  
a) XXX.XXX.X.59 as master  
b) XXX.XXX.X.60 and XXX.XXX.X.61 as data nodes.

I have installed searchguard plugin on all these nodes and generated TLS certificates by running  
install\_demo\_configuration.sh script.

now I want to restrict the communication of this cluster to other external IPs say: XXX.XXX.X.70, XXX.XXX.X.62 .

Do I need to generate certificates for above IPs also?

How can I do this. What changes do I need to make for elasticsearch.yml file

Please provide me assistance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 22, 2017, 10:44am UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/4 "2017-06-22T10:44:56Z")

</div>

I think you'd have more luck asking on the searchguard forums 🙂

---

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [June 22, 2017, 10:56am UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/5 "2017-06-22T10:56:52Z")

</div>

Ok Thank you .

---

<div class="post-metadata">

**Author:** ![navyagoli](https://avatars.discourse-cdn.com/v4/letter/n/7bcc69/32.png) [@navyagoli](https://discuss.elastic.co/u/navyagoli)\
**Post date:** [June 22, 2017, 11:16am UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/6 "2017-06-22T11:16:40Z")

</div>

Can I use NGINX to restrict IPs for elasticsearch communication.

If yes please provide me the steps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2017, 11:16am UTC](https://discuss.elastic.co/t/restrict-communication-to-elsticsearch-cluster-using-searchguard/90317/7 "2017-07-20T11:16:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
