Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HAproxy: right way to redirect old domain?

    Scheduled Pinned Locked Moved Cache/Proxy
    9 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sgw
      last edited by

      We run a webserver behind HAproxy on pfsense, with wordpress in it (docker containers, btw).
      Works great.

      Now we have other URLs/domains (= customer bought another company) which should be silently forwarded to our main domain. I set up a CNAME record ... and wonder how to solve that:

      wordpress doesn't know about the old domain names, so the redirect should happen before somehow.

      I played with some ACLs etc but so far didn't succeed. Does anyone have a nice pointer for me?

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by

        Two different domain should be forwarded to the same website ? rewrite condition for apache/nginx is not a solution?

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        S dragoangelD 2 Replies Last reply Reply Quote 0
        • S
          sgw @kiokoman
          last edited by

          @kiokoman I think, no: there has to be SSL/TLS at the front, so I need a LE-cert and a frontend for that, right? Otherwise the cert for the new domain wouldn't match the URL of the old domain.

          I look for the right "layer" on which to solve that in an elegant and correct way.

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8
            last edited by kiokoman

            if it's only for letsencrypt you can add all the domains you want inside the same cert.
            expand the cert with the new domain, the flag for certbot is -d DOMAINS "Comma-separated list of domains to obtain a certificate for"
            in any case maybe someone else can give you a better solution.

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            S 1 Reply Last reply Reply Quote 0
            • S
              sgw @kiokoman
              last edited by

              @kiokoman customer doesn't want such a multi-domain cert ... ;-)

              So I want a second HA-frontend with the matching cert for the old domain (I have that already) .. and this one should redirect. I think of some HAproxy-rule or a lua-file or so.

              1 Reply Last reply Reply Quote 0
              • dragoangelD
                dragoangel @kiokoman
                last edited by

                @kiokoman what a point use backend redirect when you have haproxy?

                Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                Unifi AP-AC-LR with EAP RADIUS, US-24

                1 Reply Last reply Reply Quote 0
                • dragoangelD
                  dragoangel
                  last edited by dragoangel

                  @sgw you not need lua, doh. Try send answer but banned by antispam lol... Send you help in pm

                  Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                  Unifi AP-AC-LR with EAP RADIUS, US-24

                  1 Reply Last reply Reply Quote 0
                  • kiokomanK
                    kiokoman LAYER 8
                    last edited by

                    that's why i said "maybe someone else can give you a better solution"
                    but i think that after 2 month he already solved the problem...

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      sgw @kiokoman
                      last edited by

                      thread is obsolete now (at least for us): moved the containers to an external host and solved the forwarding within traefik. thanks all ...

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.