# Client connection to cluster through a Proxy

**URL:** <https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020>\
**Category:** Clients\
**Created:** [7 November 2023 14:49 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020 "2023-11-07T14:49:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![pgfitzpatrick](https://avatars.discourse-cdn.com/v4/letter/p/4da419/32.png) [@pgfitzpatrick](https://forum.confluent.io/u/pgfitzpatrick)\
**Post date:** [7 November 2023 14:49 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020/1 "2023-11-07T14:49:12Z")

</div>

We are trying to connect to our kafka cluster through our corporate proxy server.  
(on prem client → proxy server → kafka cluster in cloud).  
When testing the connection using CLI, there is no means to specify a proxy server to facilitate the connection.  
Looking for assistance on how to configure the connection.  
Thanks  
Patrick

**./bin/kafka-console-producer.sh --topic --producer.config ./config/producer.properties --bootstrap-server my.instance.name:xxxx**

---

<div class="post-metadata">

**Author:** ![dtroiano](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/dtroiano/32/1961_2.png) [@dtroiano](https://forum.confluent.io/u/dtroiano)\
**Post date:** [7 November 2023 15:20 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020/2 "2023-11-07T15:20:55Z")

</div>

Hi @pgfitzpatrick,

The console producer doesn’t support proxying, and more generally the Kafka protocol isn’t conducive to using a proxy because clients need direct individual broker connectivity.

Dave

---

<div class="post-metadata">

**Author:** ![pgfitzpatrick](https://avatars.discourse-cdn.com/v4/letter/p/4da419/32.png) [@pgfitzpatrick](https://forum.confluent.io/u/pgfitzpatrick)\
**Post date:** [7 November 2023 15:27 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020/3 "2023-11-07T15:27:25Z")

</div>

Hi Dave,  
thanks for the prompt reply. Just to clarify - for some of our internal clients that have custom java consumers/producers; then the use of a proxy is not possible (direct conn is required)?  
Would the same apply for confluent replicator?  
replicator → Proxy Server - \> Kafka Cluster  
Thanks  
Patrick

---

<div class="post-metadata">

**Author:** ![dtroiano](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/dtroiano/32/1961_2.png) [@dtroiano](https://forum.confluent.io/u/dtroiano)\
**Post date:** [7 November 2023 16:04 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020/4 "2023-11-07T16:04:16Z")

</div>

Hi @pgfitzpatrick,

> thanks for the prompt reply. Just to clarify - for some of our internal clients that have custom java consumers/producers; then the use of a proxy is not possible (direct conn is required)?

Yes I’d say it’s not recommended. It might technically be possible with some proxy config and DNS creativity, but this wouldn’t be recommended. Quoting [this](https://stackoverflow.com/a/60443903/5587460) SO answer from @OneCricketeer:

> Any Proxy would need to know each individual address, and thus defeats the purpose of having a single load-balanced proxy anyway. The Kafka protocol handles its own load balancing and bootstrapping.

> Would the same apply for confluent replicator?  
> replicator → Proxy Server - \> Kafka Cluster

Yes, the same applies since Replicator is built on Connect which is built on the same Java Producer/Consumer client that your internal clients are using.

Dave

---

<div class="post-metadata">

**Author:** ![Shcamerse](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@Shcamerse](https://forum.confluent.io/u/Shcamerse)\
**Post date:** [18 January 2024 12:23 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020/5 "2024-01-18T12:23:10Z")

</div>

Connecting to a Kafka cluser through a corporate proxy server can be a bit tricky, but it’s doable. You might not have a direct option in the CLI, but you can work around it.

---

<div class="post-metadata">

**Author:** ![Shcamerse](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@Shcamerse](https://forum.confluent.io/u/Shcamerse)\
**Post date:** [20 January 2024 17:07 UTC](https://forum.confluent.io/t/client-connection-to-cluster-through-a-proxy/9020/6 "2024-01-20T17:07:10Z")

</div>

Consider setting up a [proxy site](http://pyproxy.com/?utm-source=crd&utm-keyword=?s1111) that sits between your on-prem client and the Kafka cluster in the cloud. Then, configure your client to connect to the site instead. The site should handle the communication with the Kafka cluster, forwarding your requests.  
Make sure to consult your corporate IT or network team for guidance on proxy server configurations and any security considerations. With the right setup, you should be able to establish a connection smoothly.
