HAProxy backend over VPN

  • I need to define an HAProxy backend over an (existing) IPSEC VPN. The backend seems unreachable and I can see the packets are going out on WAN instead of going into the tunnel. I guess it’s because the source doesn’t match the IPSEC policy, but as the Firewall itself has not an IP in the defined Local subnet in IPSEC I have no idea how to fix that.
    Haproxy itself is on WAN.
    Any ideas?

