Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HA proxy with ssl

    Scheduled Pinned Locked Moved pfSense Packages
    4 Posts 2 Posters 117 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rajbps
      last edited by

      I have pfsense 2.8 recent upgrade from 2.7 and HAproxy installed. I have 2 frontend http and https.
      https is set as ssl/https/tcp mode. I have a few systems like a few mail servers, nextcloud and ispconfig running a few websites. Let`s say for this example, my domain is contose.com and the mail server is contoso.com. The website contoso.com is on ispconfig. I have added it now as ssl and I can see when my phone try to sync emails, its showing an error every so often as its getting the certificate from contoso.com and not mail.contose.com. Any idea what could be wrong please?

      rajbps

      R GertjanG 2 Replies Last reply Reply Quote 0
      • R
        rajbps @rajbps
        last edited by

        hi team anyone could advise please?

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @rajbps
          last edited by Gertjan

          @rajbps said in HA proxy with ssl:

          not mail.contose.com.

          Where does the MX record of your domain contose.com points to ?
          IT should be "mail.contose.com", so the phone connects to, "mail.contose.com" and from there the mail server should uses a certificate that includes then SAN "mail.contose.com" (or a wildcard *.contose.com").

          That's for the 'normal' case.
          I can't tell if HAproxy works with your mail server also (if that's even possible)

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • R
            rajbps
            last edited by

            @Gertjan said in HA proxy with ssl:

            not mail.contose.com.

            @Gertjan I have 2 isp and mail.contose points to those ip addresses and MX. I am using a linux mail server. I have a DV cert installed on each server. for my web server I have added the following:

            f12dc686-bf5e-4470-893e-fe8317269460-image.png

            6940d697-2a2b-4945-b93b-535c91cf9676-image.png

            and the default backend for that rule is httpswww-copy

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.