# TransportClient & Authentication

**URL:** <https://discuss.elastic.co/t/transportclient-authentication/7235>\
**Category:** Elasticsearch\
**Created:** [April 5, 2012, 1:58am UTC](https://discuss.elastic.co/t/transportclient-authentication/7235 "2012-04-05T01:58:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_jain/32/834_2.png) [@Eric\_Jain](https://discuss.elastic.co/u/Eric_Jain)\
**Post date:** [April 5, 2012, 1:58am UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/1 "2012-04-05T01:58:16Z")

</div>

If the elasticsearch nodes are running on a different network (or in a  
different ec2 security group), how do I connect using the Java  
TransportClient?

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [April 8, 2012, 5:51pm UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/2 "2012-04-08T17:51:21Z")

</div>

There ins't a built in option for "security", you can possibly channel it  
through an ssh tunnel?

On Thu, Apr 5, 2012 at 4:58 AM, Eric Jain [eric.jain@gmail.com](mailto:eric.jain@gmail.com) wrote:

> If the elasticsearch nodes are running on a different network (or in a  
> different ec2 security group), how do I connect using the Java  
> TransportClient?

---

<div class="post-metadata">

**Author:** ![Eric\_Jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_jain/32/834_2.png) [@Eric\_Jain](https://discuss.elastic.co/u/Eric_Jain)\
**Post date:** [April 9, 2012, 7:10am UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/3 "2012-04-09T07:10:54Z")

</div>

On Sun, Apr 8, 2012 at 10:51, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:

> There ins't a built in option for "security", you can possibly channel it  
> through an ssh tunnel?

Do the servers need to connect back to the client when using either  
the TransportClient or the default client?

---

<div class="post-metadata">

**Author:** ![Eric\_Jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_jain/32/834_2.png) [@Eric\_Jain](https://discuss.elastic.co/u/Eric_Jain)\
**Post date:** [April 11, 2012, 7:40am UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/4 "2012-04-11T07:40:21Z")

</div>

On Apr 8, 10:51 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:

> There ins't a built in option for "security", you can possibly channel it  
> through an ssh tunnel?

Also: If there are several elasticsearch servers in the cluster, REST  
API requests can go through a load balancer. But I'm not sure the same  
is possible with an SSH tunnel for the Java API?

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [April 11, 2012, 9:23am UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/5 "2012-04-11T09:23:09Z")

</div>

For the TransportClient, no, the connection is only from the client to the  
cluster. With NodeClient, the master needs to connect to the client in  
order to notify it with events (potentially, we could have used the same  
connection from the client to the cluster to notify for events, but  
currently it requires a connection from the "cluster" to the node client).

On Mon, Apr 9, 2012 at 10:10 AM, Eric Jain [eric.jain@gmail.com](mailto:eric.jain@gmail.com) wrote:

> On Sun, Apr 8, 2012 at 10:51, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:
> 
> > There ins't a built in option for "security", you can possibly channel it  
> > through an ssh tunnel?
> 
> Do the servers need to connect back to the client when using either  
> the TransportClient or the default client?

---

<div class="post-metadata">

**Author:** ![Eric\_Jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_jain/32/834_2.png) [@Eric\_Jain](https://discuss.elastic.co/u/Eric_Jain)\
**Post date:** [April 11, 2012, 6:03pm UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/6 "2012-04-11T18:03:49Z")

</div>

On Wed, Apr 11, 2012 at 02:23, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:

> For the TransportClient, no, the connection is only from the client to the  
> cluster [...]

So TransportClient could work, but in order to connect to a cluster  
from outside without opening port 9300 to the world I'd have to set up  
an ssh tunnel to an ssh load balancer that knows which machines are  
running elasticearch. Is this really the simplest solution?

The use case is using a cluster of elasticsearch instances on EC2 from  
an application deployed on Heroku (also running on EC2, but in a  
different security group).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:32am UTC](https://discuss.elastic.co/t/transportclient-authentication/7235/7 "2017-07-06T03:32:53Z")

</div>


