<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure Splunk instance with 2 IP addresses ? in Security</title>
    <link>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24691#M815</link>
    <description>&lt;P&gt;I haven't solved it yet.I will try SPLUNK_BINDIP=* tomorrow, but for the security reason, 2 domains with separate sub-network cannot connect together, so if iam in 192.168.194.0, searchhead is resolved to 192.168.194.80. And i can't open the splunk web page on &lt;A href="http://178.17.0.80:"&gt;http://178.17.0.80:&lt;/A&gt;&lt;YOURPORT&gt; from inside 192.168.194.0.&lt;BR /&gt;
The thing i want is to connect splunk web page with the hostname, no matter what source it's from.&lt;/YOURPORT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Nov 2012 18:43:15 GMT</pubDate>
    <dc:creator>sieutruc</dc:creator>
    <dc:date>2012-11-06T18:43:15Z</dc:date>
    <item>
      <title>Configure Splunk instance with 2 IP addresses ?</title>
      <link>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24689#M813</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;I have a Splunk server configured with 2 interfaces (178.17.0.80, 192.168.194.80, hostname=searchhead).In splunklaunch.conf, i bind Splunk's IP to 178.17.0.80. &lt;BR /&gt;
I can connect to Splunk inside network 178.17.0.0, but not in network 192.168.194.0. This Splunk machine has name server configured from DNS server of each network to make sure the hostname "searchhead" be resolved to the correct ip address. &lt;BR /&gt;
So my question is how to connect to Splunk web from 2 networks that uses only common hostname "searchhead" ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2012 13:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24689#M813</guid>
      <dc:creator>sieutruc</dc:creator>
      <dc:date>2012-11-06T13:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk instance with 2 IP addresses ?</title>
      <link>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24690#M814</link>
      <description>&lt;P&gt;hi sieutruc&lt;/P&gt;

&lt;P&gt;sounds more like a routing problem, if you bind splunk to IP 178.17.0.80 you must have a network route to reach it from inside 192.168.194.0.&lt;/P&gt;

&lt;P&gt;are you able to do the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;'ping searchhead' from inside 192.168.194.0, it resolves to the correct IP and you get an answer?&lt;/LI&gt;
&lt;LI&gt;are you able to open the splunk web page on &lt;CODE&gt;&lt;A href="http://178.17.0.80:&amp;lt;yourport&amp;gt;" target="test_blank"&gt;http://178.17.0.80:&amp;lt;yourport&amp;gt;&lt;/A&gt;;&lt;/CODE&gt; from inside 192.168.194.0?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;update:&lt;BR /&gt;
why don't you unset the SPLUNK_BINDIP option so it binds to '*' ?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; SPLUNK_BINDIP=&amp;lt;ip address&amp;gt;
 * If unset, Splunk makes no specific request operating system when binding to
 ports/opening a listening socket.  This means it effectively binds to '*' or
 an unspecified bind.  The exact result of this is contolled by operating
 system behavior and configuration.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;cheers,&lt;/P&gt;

&lt;P&gt;MuS&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2012 13:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24690#M814</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-11-06T13:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk instance with 2 IP addresses ?</title>
      <link>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24691#M815</link>
      <description>&lt;P&gt;I haven't solved it yet.I will try SPLUNK_BINDIP=* tomorrow, but for the security reason, 2 domains with separate sub-network cannot connect together, so if iam in 192.168.194.0, searchhead is resolved to 192.168.194.80. And i can't open the splunk web page on &lt;A href="http://178.17.0.80:"&gt;http://178.17.0.80:&lt;/A&gt;&lt;YOURPORT&gt; from inside 192.168.194.0.&lt;BR /&gt;
The thing i want is to connect splunk web page with the hostname, no matter what source it's from.&lt;/YOURPORT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2012 18:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24691#M815</guid>
      <dc:creator>sieutruc</dc:creator>
      <dc:date>2012-11-06T18:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk instance with 2 IP addresses ?</title>
      <link>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24692#M816</link>
      <description>&lt;P&gt;Alternatively you could use use port fowarding using iptables or netsh depending on platform.&lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
#Linux&lt;BR /&gt;
iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 8000 -j DNAT --to 192.168.194.80:8000&lt;BR /&gt;
iptables -A FORWARD -p tcp -d 192.168.194.80 --dport 8000 -j ACCEPT&lt;BR /&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
#Windows&lt;BR /&gt;
netsh interface portproxy add v4tov4 listenport=8000 listenaddress=192.168.194.80 connectport=8000 connectaddress=178.17.0.80&lt;BR /&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc731068(v=ws.10).aspx#BKMK_1"&gt;Netsh_PortProxy&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.linuxmanpages.com/man8/iptables.8.php"&gt;iptables&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps or gets you started. &lt;BR /&gt;
Cheers,&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 03:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Configure-Splunk-instance-with-2-IP-addresses/m-p/24692#M816</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2012-11-07T03:18:35Z</dc:date>
    </item>
  </channel>
</rss>

