Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    503s on non-offloaded backends

    Scheduled Pinned Locked Moved Cache/Proxy
    2 Posts 1 Posters 283 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • senseivitaS
      senseivita
      last edited by senseivita

      I'm getting 503s on some HTTP backends, not all. And, when I setup SNI, no backend works except the loopback to the offloading frontend.

      If that wasn't clear:
      HTTP/80 - some backends work, some don't -- both working and non-working backends have green health checks
      HTTP-SNI/443 - nothing works -- all health checks are green
      Offloading frontends/backends -- everything works perfectly -- all health checks are green

      Turning off the health check doesn't make a difference. :(

      Where can I get the logs from HAProxy? I want to try to fix it. Thanks!

      Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

      1 Reply Last reply Reply Quote 0
      • senseivitaS
        senseivita
        last edited by

        Since I wrote this I kept testing and discovered that there's something wrong with the software itself--I think; I've been using de dev version (haproxy18-1.8.23-ish) since forever so I thought it was my own fault for not using the official one, but, I downgraded to the official version (haproxy17-1.7.12-ish) and it got worse.

        Now neither TLS termination/offloading nor SNI work. It shows something about the data not being complete:
        Screen Shot 2020-01-28 at 19.33.44.png

        Like if it were being corrupted somewhere. I tried different connections to the same result. I thought, maybe other tools like Suricata and ntopng were getting in the way but disabling them (and clearing the states) made no diff.

        I wanted to send logs to help out devs but I have none. I forgot to set them. My bad. :)

        When I switched back to the dev version things got working again but I've seen this tends to last like for a little while only. I've also observed that on the SNI front when all backends inevitably fail, the loopback backend (for the offloading front) is the only backend that works--as I mentioned earlier, offloading and http work fine.

        I'll set up a logging server for the next time. :)

        Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.