Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ACL conditions

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    7 Posts 2 Posters 802 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      ed.be
      last edited by

      Hi everyone,
      i need to configure HAProxy to be used with "AND" condition, to filter the traffic using our alias "vCD_OK_Clienti", can i ask you some support to do this ? thanks!1111.PNG

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @ed.be
        last edited by

        @ed-be
        Configure both ACLs with different names(!). Then enter both into the action conditions field separated by a space.

        E 1 Reply Last reply Reply Quote 0
        • E
          ed.be @viragomann
          last edited by

          @viragomann Thanks for the reply i've now a problem with a redirect, giving us a 502 bad gateway error.

          I think now that my main issue, it's, instead of the ip after "name"[name ------IP---------:443] (arrow) i need to use our fqdn, but i was unable from the pfsense GUI.
          2222.PNG

          note:
          Both IPs in the bind parameter are the same .

          3333.PNG

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @ed.be
            last edited by

            @ed-be
            Check the stats if the backend is even shown as online.
            I guess, it isn't. Then try with Basic health check in the backend settings.
            You have enabled HTTP checks, but this needs some configuration effort.

            E 1 Reply Last reply Reply Quote 0
            • E
              ed.be @viragomann
              last edited by

              @viragomann

              Thanks again, i've checked and everything is runnng fine, below some screens:

              14444.PNG

              4444.PNG

              5555.PNG

              Any ideas ? i'm start losing hope.

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @ed.be
                last edited by

                @ed-be
                I suspect, it's due to the way you redirect the traffic to the backends.
                Your config shows public backend IPs (maybe you want to hide them). So are these IPs behind pfSense or are these IPs assigned to WAN?
                The latter won't work, I think.

                E 1 Reply Last reply Reply Quote 0
                • E
                  ed.be @viragomann
                  last edited by

                  @viragomann said in ACL conditions:

                  So are these IPs behind pfSense or are these IPs assigned to WAN?

                  Ok, so we are using this in L4 mode, and it's working fine. To reply to you we have no need to hide those public IPs, for us those are on a DMZ assigned to our WAN, so it's ok.

                  Thanks for your support Virago, sadly we are struggling a bit on this.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.