diff --git a/conf/cassandra-env.sh b/conf/cassandra-env.sh index 354442691c..dfe8184522 100644 --- a/conf/cassandra-env.sh +++ b/conf/cassandra-env.sh @@ -157,6 +157,7 @@ fi # Specifies the default port over which Cassandra will be available for # JMX connections. +# For security reasons, you should not expose this port to the internet. Firewall it if needed. JMX_PORT="7199" diff --git a/conf/cassandra.yaml b/conf/cassandra.yaml index 45290aac12..99f13a684c 100644 --- a/conf/cassandra.yaml +++ b/conf/cassandra.yaml @@ -318,6 +318,7 @@ listen_address: localhost # same as the rpc_address. The port however is different and specified below. start_native_transport: true # port for the CQL native transport to listen for clients on +# For security reasons, you should not expose this port to the internet. Firewall it if needed. native_transport_port: 9042 # The maximum threads for handling requests when the native transport is used. # This is similar to rpc_max_threads though the default differs slightly (and @@ -341,6 +342,8 @@ start_rpc: true # Note that unlike ListenAddress above, it is allowed to specify 0.0.0.0 # here if you want to listen on all interfaces, but that will break clients # that rely on node auto-discovery. +# +# For security reasons, you should not expose this port to the internet. Firewall it if needed. rpc_address: localhost # port for Thrift to listen for clients on rpc_port: 9160