Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to Make ACL Fail with Close Connection

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    1 Posts 1 Posters 179 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      guardian Rebel Alliance
      last edited by

      I am just beginning to experiment with HAProxy, and I would like to have a connection that fails the ACL just close (as quietly as possible) the TCP connection instead of returning 503 Service Unavailable.

      (I plan on having several services behind HAProxy on my home internet connection for my private use, so there will eventually be a much more complex ACL list, so I want a solution for -- if all above fail, then close connection, to be as boring as possible to automated scanners.)

      Here is what I have tried, but I get the following error messages:

      Errors found while starting haproxy
      [ALERT] 172/154958 (13076) : parsing [/var/etc/haproxy_test/haproxy.cfg:24] : tcp-response content is only allowed in 'backend' sections
      [ALERT] 172/154958 (13076) : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg
      [ALERT] 172/154958 (13076) : Fatal errors found in configuration.
      

      574baa18-11be-4315-8eb9-5ef8a980e04a-image.png

      Can someone suggest what I need to do.

      If you find my post useful, please give it a thumbs up!
      pfSense 2.7.2-RELEASE

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.