Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HAproxy multiple FQDN's?

    Scheduled Pinned Locked Moved Cache/Proxy
    17 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      503 Service not available is normally returned with the backend fails health check.

      I had sim issue with trying to run ombi v4 behind haproxy. v3 worked fine - but when changed to v4 something odd changed and would give 503, I changed the healthcheck to basic and started working.. set your backend check to off or change what it does for the check.

      is the traffic behind sent on to your backend? What does the haproxy log say when you try and access that fqdn?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      U 1 Reply Last reply Reply Quote 0
      • U
        unf0rg0tt3n @johnpoz
        last edited by

        @johnpoz No idea where the traffic is sent. Where do I find the haproxy logs?
        it only doesn't work for this particular domain. When I add a new domain to pfsense.
        other than dynamic dns is there another place where I need to specify the domain?

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          No - if the fqdn points to your wan IP.. Then the traffic will get there.. I am getting 503 when I hit it..

          For the Haproxy log, did you enable it in settings? You can point it to local, but you prob want to send it to remote syslog for better info..

          Sniff on the interface that is connected to your backend.. do you see traffic being sent to it on port 80?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          U 2 Replies Last reply Reply Quote 0
          • U
            unf0rg0tt3n @johnpoz
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • U
              unf0rg0tt3n @johnpoz
              last edited by unf0rg0tt3n

              @johnpoz said in HAproxy multiple FQDN's?:

              No - if the fqdn points to your wan IP.. Then the traffic will get there.. I am getting 503 when I hit it..

              For the Haproxy log, did you enable it in settings? You can point it to local, but you prob want to send it to remote syslog for better info..

              Sniff on the interface that is connected to your backend.. do you see traffic being sent to it on port 80?

              It looks like there is no traffic towards backend. Or i'm nog doing it right.
              Knipsel.JPG

              I did enable the logging.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                Well if there is no traffic towards the backend, then haproxy thinks its down.. Or you have something not right for matching on where to send it, or traffic is never hitting your wan IP (your frontend)..

                The 503 would seem to me that its not matching or the backend is down from haproxy point of view.

                You really need to send to a syslog to get informational info on what might be going on from haproxy log.

                When I hit it, get 503 and "No server is available to handle this request. "

                So either non of your matches worked, or backend is down from haproxy point of view and no point in sending on the traffic. So its sends back - sorry no server available to handle your request.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                U 1 Reply Last reply Reply Quote 0
                • U
                  unf0rg0tt3n @johnpoz
                  last edited by

                  @johnpoz thanks for the information!
                  What would the best way to sniff? Kinda new to this level of power from a firewall/router.

                  I also think the problem doesn't lie in the backend or front-end but purely the name.

                  When changing the hostnames and domain nothing is wrong amd I get forwarded correctly.

                  My main domain is dkict.com and I host various services which all work and forward to the correct backend.
                  So I set up a turnkey Linux WordPress container.
                  I wanted it to get fmsv.nl which gave 503 message.
                  When i changed the name value to: web.dkict.com it just worked and forwarded to the right backend (only a name change). Isn't that strange?

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Your name resolves to a 83.82.x.x address I take it that is correct.. I don't want to post up the IP or the full name, unless your ok with it - but you did list it in the screenshots.

                    But if the fqdn is resolving, and pointing to your IP your having the frontend listen on with port. Then you prob have something wrong with the acl and or action..

                    Try turning off your backend check.. Maybe that is what is failing..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    U 2 Replies Last reply Reply Quote 0
                    • U
                      unf0rg0tt3n @johnpoz
                      last edited by

                      @johnpoz I'm offering several public services so I thought why not actually post it. Ima check the other thing in the morning :)

                      Thanks!

                      1 Reply Last reply Reply Quote 0
                      • U
                        unf0rg0tt3n @johnpoz
                        last edited by

                        @johnpoz okay... I feel so stupid!

                        I created a new frontend, selected shared frontend and it works now.
                        Thanks for your help!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.