Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    haproxy - not working

    Scheduled Pinned Locked Moved Cache/Proxy
    18 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • VioletDragonV
      VioletDragon @TMG
      last edited by

      @TMG said in haproxy - not working:

      UDM

      UDM is a Dream Machine by Ubiquti. I would suggest having pfSense handling DNS as it will add more complexity to the solution.

      DynDNS is Dynamic DNS.

      VIP can be any IP as it's Virtual,.

      For SSL in Haproxy, the Certificate is mapped by the Frontend.

      TMGT 1 Reply Last reply Reply Quote 1
      • TMGT
        TMG @VioletDragon
        last edited by TMG

        @VioletDragon

        Nothing needs to go in here?

        a326e393-dbd8-4032-99e1-40992005b04b-image.png

        I still don't understand the connection between the VIP and the DynDns domain xxxxx.home64.de?
        How exactly this plays together.... I have been looking all day
        for a video or a configuration guide for my configuration.

        Do you mean these here, no??

        db989c93-1e55-4958-9e55-5528e353e252-image.png

        How and where exactly does the VIP come into play?

        TMGT VioletDragonV 2 Replies Last reply Reply Quote 0
        • TMGT
          TMG @TMG
          last edited by

          86af43a5-579a-48f9-b146-6d003e8906ae-image.png

          1 Reply Last reply Reply Quote 0
          • VioletDragonV
            VioletDragon @TMG
            last edited by

            @TMG Create a A Record that points to WAN.

            Under DNS Resolver -> Host Overrides. Create a Host & Domain Name, Add the IP of the VIP.

            Frontend of Haproxy needs two Entries One for Port 80 and another Port 443. Both needs the IP of VIP you created which comes under Listen address for both.

            For the SSL Certificate you specify it under Certificate. Make sure that the type is configured as http/https offloading.

            TMGT 1 Reply Last reply Reply Quote 0
            • TMGT
              TMG @VioletDragon
              last edited by

              @VioletDragon

              Port 443/80 here in Haproxy-config. ??

              16615d2a-64eb-4b3e-93ab-7db3539d0164-image.png

              VioletDragonV 1 Reply Last reply Reply Quote 0
              • VioletDragonV
                VioletDragon @TMG
                last edited by

                @TMG No. You need two frontends, one for Port 80 & Port 443.

                Listen address needs to be set to the VIP.

                Screenshot from 2023-12-14 21-28-19.png Screenshot from 2023-12-14 21-28-36.png Screenshot from 2023-12-14 21-28-55.png

                TMGT 1 Reply Last reply Reply Quote 1
                • TMGT
                  TMG @VioletDragon
                  last edited by

                  @VioletDragon
                  Good morning. I can only say thank you again and again for your efforts.
                  Must here in the dnsresolver/host_overrides also the created VIP purely

                  7a8abf6b-4957-410c-907b-e92567c467be-image.png

                  VioletDragonV 1 Reply Last reply Reply Quote 0
                  • VioletDragonV
                    VioletDragon @TMG
                    last edited by

                    @TMG Good morning, yes the IP is the VIP.

                    Depending on your OS, you can test by using Dig in Linux / macOS or nslookup in Windows.

                    Regards

                    TMGT 1 Reply Last reply Reply Quote 1
                    • TMGT
                      TMG @VioletDragon
                      last edited by

                      @VioletDragon
                      It's never happened to me before that I can't solve a problem for days. I can't get it to work?
                      dig always points to the public IP address.
                      Can you do me a big favor and take a look at the
                      pdf with the screenshots to see if you notice anything where I'm
                      am wrong ... or if something important is missing.
                      ... thanks thanks thanks
                      I just realized I can't attach a pdf?

                      TMGT 1 Reply Last reply Reply Quote 0
                      • TMGT
                        TMG @TMG
                        last edited by TMG

                        Here is a dropbox link
                        pfsense_screenshots

                        If you don't want that, please let me know. Maybe we can find another way.

                        VioletDragonV 1 Reply Last reply Reply Quote 0
                        • VioletDragonV
                          VioletDragon @TMG
                          last edited by

                          @TMG Attach Screenshots of DNS Resolver. Screenshots in pdf are small, Also attach screenshots of System -> General Setup & System -> Advanced -> Admin Access.

                          Regards

                          TMGT 1 Reply Last reply Reply Quote 1
                          • TMGT
                            TMG @VioletDragon
                            last edited by

                            @VioletDragon
                            I hope it´s bigger and you can read it

                            pfsense_2

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.