diff --git a/conf/cassandra-env.sh b/conf/cassandra-env.sh index 3f4c21b088..d6147746f4 100644 --- a/conf/cassandra-env.sh +++ b/conf/cassandra-env.sh @@ -162,6 +162,7 @@ fi # Specifies the default port over which Cassandra will be available for # JMX connections. +# For security reasons, you should not expose this port to the internet. Firewall it if needed. JMX_PORT="7199" diff --git a/conf/cassandra.yaml b/conf/cassandra.yaml index 0b114aa078..f337067dad 100644 --- a/conf/cassandra.yaml +++ b/conf/cassandra.yaml @@ -384,6 +384,7 @@ listen_address: localhost # same as the rpc_address. The port however is different and specified below. start_native_transport: true # port for the CQL native transport to listen for clients on +# For security reasons, you should not expose this port to the internet. Firewall it if needed. native_transport_port: 9042 # The maximum threads for handling requests when the native transport is used. # This is similar to rpc_max_threads though the default differs slightly (and @@ -409,6 +410,8 @@ start_rpc: true # # Note that unlike listen_address, you can specify 0.0.0.0, but you must also # set broadcast_rpc_address to a value other than 0.0.0.0. +# +# For security reasons, you should not expose this port to the internet. Firewall it if needed. rpc_address: localhost # rpc_interface: eth1