• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

HAproxy: right way to redirect old domain?

Scheduled Pinned Locked Moved Cache/Proxy
9 Posts 3 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sgw
    last edited by Jul 17, 2019, 6:15 PM

    We run a webserver behind HAproxy on pfsense, with wordpress in it (docker containers, btw).
    Works great.

    Now we have other URLs/domains (= customer bought another company) which should be silently forwarded to our main domain. I set up a CNAME record ... and wonder how to solve that:

    wordpress doesn't know about the old domain names, so the redirect should happen before somehow.

    I played with some ACLs etc but so far didn't succeed. Does anyone have a nice pointer for me?

    1 Reply Last reply Reply Quote 0
    • K
      kiokoman LAYER 8
      last edited by Jul 17, 2019, 7:17 PM

      Two different domain should be forwarded to the same website ? rewrite condition for apache/nginx is not a solution?

      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
      Please do not use chat/PM to ask for help
      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

      S D 2 Replies Last reply Jul 17, 2019, 7:49 PM Reply Quote 0
      • S
        sgw @kiokoman
        last edited by Jul 17, 2019, 7:49 PM

        @kiokoman I think, no: there has to be SSL/TLS at the front, so I need a LE-cert and a frontend for that, right? Otherwise the cert for the new domain wouldn't match the URL of the old domain.

        I look for the right "layer" on which to solve that in an elegant and correct way.

        1 Reply Last reply Reply Quote 0
        • K
          kiokoman LAYER 8
          last edited by kiokoman Jul 17, 2019, 8:02 PM Jul 17, 2019, 7:56 PM

          if it's only for letsencrypt you can add all the domains you want inside the same cert.
          expand the cert with the new domain, the flag for certbot is -d DOMAINS "Comma-separated list of domains to obtain a certificate for"
          in any case maybe someone else can give you a better solution.

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          S 1 Reply Last reply Jul 18, 2019, 11:20 AM Reply Quote 0
          • S
            sgw @kiokoman
            last edited by Jul 18, 2019, 11:20 AM

            @kiokoman customer doesn't want such a multi-domain cert ... ;-)

            So I want a second HA-frontend with the matching cert for the old domain (I have that already) .. and this one should redirect. I think of some HAproxy-rule or a lua-file or so.

            1 Reply Last reply Reply Quote 0
            • D
              dragoangel @kiokoman
              last edited by Aug 28, 2019, 7:50 AM

              @kiokoman what a point use backend redirect when you have haproxy?

              Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
              Unifi AP-AC-LR with EAP RADIUS, US-24

              1 Reply Last reply Reply Quote 0
              • D
                dragoangel
                last edited by dragoangel Aug 28, 2019, 8:06 AM Aug 28, 2019, 8:04 AM

                @sgw you not need lua, doh. Try send answer but banned by antispam lol... Send you help in pm

                Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                Unifi AP-AC-LR with EAP RADIUS, US-24

                1 Reply Last reply Reply Quote 0
                • K
                  kiokoman LAYER 8
                  last edited by Aug 28, 2019, 8:26 AM

                  that's why i said "maybe someone else can give you a better solution"
                  but i think that after 2 month he already solved the problem...

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  S 1 Reply Last reply Aug 28, 2019, 10:21 AM Reply Quote 0
                  • S
                    sgw @kiokoman
                    last edited by Aug 28, 2019, 10:21 AM

                    thread is obsolete now (at least for us): moved the containers to an external host and solved the forwarding within traefik. thanks all ...

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      [[user:consent.lead]]
                      [[user:consent.not_received]]