<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[503s on non-offloaded backends]]></title><description><![CDATA[<p dir="auto">I'm getting 503s on <em>some</em> HTTP backends, not all. And, when I setup SNI, no backend works except the loopback to the offloading frontend.</p>
<p dir="auto">If that wasn't clear:<br />
HTTP/80 - some backends work, some don't -- both working and non-working backends have green health checks<br />
HTTP-SNI/443 - nothing works -- all health checks are green<br />
Offloading frontends/backends -- everything works perfectly -- all health checks are green</p>
<p dir="auto">Turning off the health check doesn't make a difference. :(</p>
<p dir="auto">Where can I get the logs from HAProxy? I want to try to fix it. Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/148334/503s-on-non-offloaded-backends</link><generator>RSS for Node</generator><lastBuildDate>Tue, 16 Jun 2026 09:09:35 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/148334.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 22 Nov 2019 20:01:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 503s on non-offloaded backends on Wed, 29 Jan 2020 03:07:16 GMT]]></title><description><![CDATA[<p dir="auto">Since I wrote this I kept testing and discovered that there's something wrong with the software itself--I think; I've been using de dev version (haproxy18-1.8.23-ish) since forever so I thought it was my own fault for not using the official one, <em>but</em>, I downgraded to the official version (haproxy17-1.7.12-ish) and it got worse.</p>
<p dir="auto">Now neither TLS termination/offloading nor SNI work. It shows something about the data not being complete:<br />
<img src="/assets/uploads/files/1580265548001-screen-shot-2020-01-28-at-19.33.44.png" alt="Screen Shot 2020-01-28 at 19.33.44.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Like if it were being corrupted somewhere. I tried different connections to the same result. I thought, maybe other tools like <em>Suricata</em> and <em>ntopng</em> were getting in the way but disabling them (and clearing the states) made no diff.</p>
<p dir="auto">I wanted to send logs to help out devs but I have none. I forgot to set them. My bad. :)</p>
<p dir="auto">When I switched back to the dev version things got working again but I've seen this tends to last like for a little while only. I've also observed that on the SNI front when all backends inevitably fail, the loopback backend (for the offloading front) is the only backend that works--as I mentioned earlier, <em>offloading</em> and <em>http</em> work fine.</p>
<p dir="auto">I'll set up a logging server for the next time. :)</p>
]]></description><link>https://forum.netgate.com/post/888434</link><guid isPermaLink="true">https://forum.netgate.com/post/888434</guid><dc:creator><![CDATA[senseivita]]></dc:creator><pubDate>Wed, 29 Jan 2020 03:07:16 GMT</pubDate></item></channel></rss>