• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

HAProxy forwardfor

Scheduled Pinned Locked Moved Cache/Proxy
6 Posts 2 Posters 461 Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V Offline
    varazir
    last edited by Jun 30, 2024, 12:24 PM

    Hi,

    I'm trying to setup Add an X-Forwarded-For header.

    Here is my haproxy.cfg

    It's for the Domoticz_ipvANY backend but I want it for more later.

    When I check my logs in Domoticz I only see pfSense IP connecting.

    TIA

    V 1 Reply Last reply Jun 30, 2024, 7:18 PM Reply Quote 0
    • V Offline
      viragomann @varazir
      last edited by Jun 30, 2024, 7:18 PM

      @varazir
      "Add an X-Forwarded-For header" does, what its name implies. It adds a http header in traffic sent to the backen, which contains the real client source IP.

      To get benefit of this, you have to configure your backend server to read and log the content of the X-Forwarded-For header. It might not do this out of the box.

      V 2 Replies Last reply Jun 30, 2024, 8:33 PM Reply Quote 1
      • V Offline
        varazir @viragomann
        last edited by Jun 30, 2024, 8:33 PM

        @viragomann redid the HAproxy rules and now it's working.

        1 Reply Last reply Reply Quote 0
        • V Offline
          varazir @viragomann
          last edited by Jul 7, 2024, 12:37 PM

          @viragomann Hmm, looks like it's not working.

          I did a tcpdump on the backend server and the X-Forwarded-For are not set as far as I can see in wireshark.

          V 1 Reply Last reply Jul 7, 2024, 3:58 PM Reply Quote 0
          • V Offline
            viragomann @varazir
            last edited by Jul 7, 2024, 3:58 PM

            @varazir
            You can see the http headers in the capture?

            V 1 Reply Last reply Jul 7, 2024, 5:21 PM Reply Quote 0
            • V Offline
              varazir @viragomann
              last edited by Jul 7, 2024, 5:21 PM

              @viragomann said in HAProxy forwardfor:

              @varazir
              You can see the http headers in the capture?

              yes, strange is that it's only for Authelia I don't get the header set. I think I'm going to remove it.
              Using wireguard to connect to my home network.

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received