# Restricting Elastic Cluster Access From Browser and unwanted Servers

**URL:** <https://discuss.elastic.co/t/restricting-elastic-cluster-access-from-browser-and-unwanted-servers/315208>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 26, 2022, 7:21pm UTC](https://discuss.elastic.co/t/restricting-elastic-cluster-access-from-browser-and-unwanted-servers/315208 "2022-09-26T19:21:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanjaykumr](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@sanjaykumr](https://discuss.elastic.co/u/sanjaykumr)\
**Post date:** [September 26, 2022, 7:21pm UTC](https://discuss.elastic.co/t/restricting-elastic-cluster-access-from-browser-and-unwanted-servers/315208/1 "2022-09-26T19:21:10Z")

</div>

We have 5 Node Cluster with 3 Master Nodes , 3 Coord nodes and 6 Data Nodes.  
Currently we can view the content of Elastic cluster via browser using the url ["" [http://hostname:9200/\_cat/nodes](http://hostname:9200/_cat/nodes)""] , we want access from the browser and also unwanted servers to be restricted and only allow set of servers [Forming a cluster] and App server's making call's to Elastic.

To achieve the above scenario, I have updated the following parameters' in the elastic.yaml [In Master-1/Master-2/Master-3] and after updated the elastic.yml the service isn't starting up. Please  
assist me if I am missing something or any additional steps have to be performed.  
xpack.security.enabled: trye  
xpack.security.transport.filter.allow: ["Hostname1", "Hostname2", "Hostname3", "Hostname n"]  
xpack.security.transport.filter.deny: \_all

Note: The above 3 are the only config related to security in the elastic.yml

Also please let me know if security related config has to be update on all Nodes [All Masters, All Co-ord's and all Data nodes]

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 27, 2022, 2:41am UTC](https://discuss.elastic.co/t/restricting-elastic-cluster-access-from-browser-and-unwanted-servers/315208/2 "2022-09-27T02:41:18Z")

</div>

Why it is not starting? What do you have in the logs? What nodes did you put in the `allow` option? You should put **all** of your elasticsearch nodes.

Did you have security enabled before?

Please share your log with the error.

Also, while you can use this filter in elastiscearch, it would be better to use a firewall service to allow or deny the requests.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2022, 2:42am UTC](https://discuss.elastic.co/t/restricting-elastic-cluster-access-from-browser-and-unwanted-servers/315208/3 "2022-10-25T02:42:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
