# Unable to connect to kibana and elastic after enabling security

**URL:** <https://discuss.elastic.co/t/unable-to-connect-to-kibana-and-elastic-after-enabling-security/197954>\
**Category:** Kibana\
**Created:** [September 3, 2019, 9:29pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana-and-elastic-after-enabling-security/197954 "2019-09-03T21:29:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![megan\_b](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@megan\_b](https://discuss.elastic.co/u/megan_b)\
**Post date:** [September 3, 2019, 9:29pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana-and-elastic-after-enabling-security/197954/1 "2019-09-03T21:29:35Z")

</div>

We enabled security on our cluster and are able to connect to elastic and to kibana from the nodes inside the cluster, but when we attempt to connect from an 'outside' system the connection is reset by the server after being presented the TLS client hello. Have confirmed that all network connectivity in the middle is fine, ufw is not running on the hosts, and running tcpdump on the node shows the connection being received and then reset. Is there some additional xpack or kibana configuration we're missing? Everything seems to be running smoothly and error free inside the cluster, we just can't connect from outside. Not even getting to the point where it says the connection is unauthorized, it just flat resets it once it receives the client hello.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [September 3, 2019, 10:22pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana-and-elastic-after-enabling-security/197954/2 "2019-09-03T22:22:00Z")

</div>

Try `curl -k -u "userid" -XGET "https://your.host:9200"`

If that works, security -k nullifies is the problem.

---

<div class="post-metadata">

**Author:** ![megan\_b](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@megan\_b](https://discuss.elastic.co/u/megan_b)\
**Post date:** [September 4, 2019, 2:10pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana-and-elastic-after-enabling-security/197954/3 "2019-09-04T14:10:47Z")

</div>

Using -k doesn't make a difference. The connection is reset by the server after the client hello, so the client doesn't even have a chance to reject the connection based on whether it trusts the certificate or not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2019, 2:10pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana-and-elastic-after-enabling-security/197954/4 "2019-10-02T14:10:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
