Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Not understanding the HA Proxy flow for one backend server

    Scheduled Pinned Locked Moved Cache/Proxy
    2 Posts 1 Posters 925 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      michmoor LAYER 8 Rebel Alliance
      last edited by

      I have HA proxy set up with multiple backend servers for various applications working without issue.
      I decided to install NextCloud on my VM instance. Its sitting in my DMZ vlan[192.168.15.0/24]
      Here is the weirdness..

      If i connect directly to the nextcloud dmz IP - 192.168.15.102 , i get the landing page. I can log in. All is well.

      If i connect through my HA proxy - and here is the weird part - i eventually get a 504 Gateway timed out but in the firewall logs I see my HA proxy establishing the TCP 3 way handshake, i even see a GET request from my proxy but after a few seconds i see my nextcloud server sending out DNS Queries for nextcloud.mydomain.com and then I see the server attempting to establish a 3-way handshake with my proxy - sending a SYN.

      I have never seen this behaviour at all with my other apps. Im zeroing in on a HA Proxy misconfig possibly as bypassing the proxy everything works as expected.

      Ideas?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      M 1 Reply Last reply Reply Quote 0
      • M Offline
        michmoor LAYER 8 Rebel Alliance @michmoor
        last edited by

        @michmoor This was solved on my end. Was an issue with the backend server domain-name vs. hostname configured.

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.