# Web Portocols and Ports used by Elasticsearch

**URL:** <https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055>\
**Category:** Elasticsearch\
**Created:** [February 19, 2020, 7:42pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055 "2020-02-19T19:42:55Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![somebody](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@somebody](https://discuss.elastic.co/u/somebody)\
**Post date:** [February 19, 2020, 7:42pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/1 "2020-02-19T19:42:55Z")

</div>

Hi,

I need to know all the protocols ( http, tcp.. etc) Elasticsearch uses for

1. client-server communication (indexing, querying.. etc)
2. Inter-communication between primary and replica shards ( For leader election, recovery, backup.. etc)  
Or for any communication ES utilizes.  
I need this information for Network security ( which ports to secure ). Could someone help me on this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 19, 2020, 7:55pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/2 "2020-02-19T19:55:10Z")

</div>

Welcome.

Ports used are 9200 and 9300 by default.

---

<div class="post-metadata">

**Author:** ![somebody](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@somebody](https://discuss.elastic.co/u/somebody)\
**Post date:** [February 19, 2020, 7:59pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/3 "2020-02-19T19:59:50Z")

</div>

Thank you dadoonet.  
Are these the only two ports used?  
What are these ports used for and what is the protocol it is using ( http/tcp )?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 19, 2020, 8:15pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/4 "2020-02-19T20:15:06Z")

</div>

> [@somebody](#):
>
> Are these the only two ports used?

Yes.

9200 for REST Http calls  
9300 is the binary port for node to node communication

---

<div class="post-metadata">

**Author:** ![somebody](https://avatars.discourse-cdn.com/v4/letter/s/3ab097/32.png) [@somebody](https://discuss.elastic.co/u/somebody)\
**Post date:** [February 20, 2020, 7:59am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/5 "2020-02-20T07:59:10Z")

</div>

Hi dadoonet,

Thanks for the helping me with the answers.  
Is it possible to configure 9300 to take http protocol request instead of tcp?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 20, 2020, 8:17am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/6 "2020-02-20T08:17:38Z")

</div>

You need 2 different ports.  
You can also disable http (9200) if you wish. And add a coordinating node which has both 9200 and 9300 ports.

---

<div class="post-metadata">

**Author:** ![ted.fed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted.fed/32/56636_2.png) [@ted.fed](https://discuss.elastic.co/u/ted.fed)\
**Post date:** [February 20, 2020, 3:57pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/7 "2020-02-20T15:57:41Z")

</div>

We are integrating ElasticSearch with Envoy ServiceMesh.  
And want to use HTTP only everywhere instead of TCP.  
Is it possible to do that?

As of now, we are aware of only 2 ports: 9200 (http) and 9300 (tcp).

1. Is it possible to configure ES such that 9300 also becomes http?
2. Are there any ports other than the above 2 that we need to be aware of ? (In Kibana, Master nodes or Data nodes)

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 20, 2020, 5:57pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/8 "2020-02-20T17:57:09Z")

</div>

> [@ted.fed](#):
>
> We are integrating Elasticsearch with Envoy ServiceMesh.

Elasticsearch has its own "service mesh" (if you want to call it that) so I don't really see the need for an external one too. It's possible you can make this work but I don't think it will be easy. Or necessary.

> [@ted.fed](#):
>
> And want to use HTTP only everywhere instead of TCP.  
> Is it possible to do that?

No.

---

<div class="post-metadata">

**Author:** ![ted.fed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted.fed/32/56636_2.png) [@ted.fed](https://discuss.elastic.co/u/ted.fed)\
**Post date:** [February 20, 2020, 8:16pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/9 "2020-02-20T20:16:43Z")

</div>

Can you please clarify what you mean by "own service mesh" ?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 20, 2020, 9:15pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/10 "2020-02-20T21:15:20Z")

</div>

Sure. An Elasticsearch cluster is made up of lots of different components (a.k.a. services, although we don't really call them that) all running on the different nodes, but clients don't need to care about the details: you can send a HTTP request to any node in the cluster and it will work out how to split it up and route it to the right places to execute it and gather the responses back up again afterwards. It already handles all the things that you would typically ask of a service mesh: retries, failover, auto-discovery and self-healing, load-based routing, introspection and monitoring, coordination, security, etc. are all built in already.

That's not to say that you can't integrate it with a broader service ecosystem at the HTTP level, just that there's no need to bring the non-HTTP connections between nodes into that scope too.

---

<div class="post-metadata">

**Author:** ![ted.fed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted.fed/32/56636_2.png) [@ted.fed](https://discuss.elastic.co/u/ted.fed)\
**Post date:** [February 20, 2020, 9:58pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/11 "2020-02-20T21:58:27Z")

</div>

An external ServiceMesh can give features like request-specific custom-actions, access-control/security without the paid version and can even allow modifying request/responses from/to ES (although this last one is a little un-clean).

But regardless, just found out that Envoy kind of proxies can encrypt traffic at TCP level too. So we are good with TCP as well as HTTP ports for now.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2020, 10:02pm UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/12 "2020-02-20T22:02:52Z")

</div>

Our free distribution includes access control - [https://www.elastic.co/blog/security-for-elasticsearch-is-now-free](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free)

---

<div class="post-metadata">

**Author:** ![ted.fed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted.fed/32/56636_2.png) [@ted.fed](https://discuss.elastic.co/u/ted.fed)\
**Post date:** [February 21, 2020, 12:52am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/13 "2020-02-21T00:52:35Z")

</div>

Security is not really free.

As per [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions), security is free only for the basic version whose license says that it cannot be used for production.  
[https://github.com/elastic/elasticsearch/blob/7.0/licenses/ELASTIC-LICENSE.txt#L88](https://github.com/elastic/elasticsearch/blob/7.0/licenses/ELASTIC-LICENSE.txt#L88)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 21, 2020, 3:26am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/14 "2020-02-21T03:26:05Z")

</div>

I don't think that line you link to means what you think. Otherwise no one would be using the software.

What exactly are you using Elasticsearch for? Not technically, from a business point of view. If you're re-distributing our software as part of a broader product, then you would be correct about restrictions, but you should really reach out to [license@elastic.co](mailto:license@elastic.co) to discuss this.

---

<div class="post-metadata">

**Author:** ![ted.fed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted.fed/32/56636_2.png) [@ted.fed](https://discuss.elastic.co/u/ted.fed)\
**Post date:** [February 21, 2020, 3:47am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/15 "2020-02-21T03:47:25Z")

</div>

We are planning to use it for regular search kind of applications - like log-search, alternate key search, text-analysis etc.  
But we are definitely not planning to redistribute ElasticSearch.

Just planning to install ES on a bunch of computes, index data and query it.

The data and queries can come from anywhere (private or public clients), no restrictions on it but will get sanitized enough so that it does not cause problems. ServiceMesh might help a bit with sanitization too (just thinking aloud on this one).

So from the above description, is it ok to use the basic license of ES for production environment since we are not re-distributing ES itself nor are we creating any derivative product from ES ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 21, 2020, 3:54am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/16 "2020-02-21T03:54:05Z")

</div>

> [@ted.fed](#):
>
> So from the above description, is it ok to use the basic license of ES for production environment since we are not re-distributing ES itself nor are we creating any derivative product from ES ?

Yes, it is.

---

<div class="post-metadata">

**Author:** ![Lawrence63](https://avatars.discourse-cdn.com/v4/letter/l/f0a364/32.png) [@Lawrence63](https://discuss.elastic.co/u/Lawrence63)\
**Post date:** [March 12, 2020, 8:52am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/17 "2020-03-12T08:52:19Z")

</div>

The most important settings to make a successful connection are the Elasticsearch cluster name and the discovery mode. Graylog is able to discover the Elasticsearch nodes using multicast.

---

<div class="post-metadata">

**Author:** ![Lawrence63](https://avatars.discourse-cdn.com/v4/letter/l/f0a364/32.png) [@Lawrence63](https://discuss.elastic.co/u/Lawrence63)\
**Post date:** [March 24, 2020, 10:37am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/18 "2020-03-24T10:37:22Z")

</div>

> [@Lawrence63](#):
>
> The most important settings to make a successful connection are the Elasticsearch cluster name and the discovery mode. Graylog is able to discover the Elasticsearch nodes using multicast

Any other suggestion ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2020, 10:37am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055/19 "2020-04-21T10:37:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
