• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Not understanding the HA Proxy flow for one backend server

Scheduled Pinned Locked Moved Cache/Proxy
2 Posts 1 Posters 801 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    michmoor LAYER 8 Rebel Alliance
    last edited by Mar 18, 2023, 12:22 AM

    I have HA proxy set up with multiple backend servers for various applications working without issue.
    I decided to install NextCloud on my VM instance. Its sitting in my DMZ vlan[192.168.15.0/24]
    Here is the weirdness..

    If i connect directly to the nextcloud dmz IP - 192.168.15.102 , i get the landing page. I can log in. All is well.

    If i connect through my HA proxy - and here is the weird part - i eventually get a 504 Gateway timed out but in the firewall logs I see my HA proxy establishing the TCP 3 way handshake, i even see a GET request from my proxy but after a few seconds i see my nextcloud server sending out DNS Queries for nextcloud.mydomain.com and then I see the server attempting to establish a 3-way handshake with my proxy - sending a SYN.

    I have never seen this behaviour at all with my other apps. Im zeroing in on a HA Proxy misconfig possibly as bypassing the proxy everything works as expected.

    Ideas?

    Firewall: NetGate,Palo Alto-VM,Juniper SRX
    Routing: Juniper, Arista, Cisco
    Switching: Juniper, Arista, Cisco
    Wireless: Unifi, Aruba IAP
    JNCIP,CCNP Enterprise

    M 1 Reply Last reply Apr 10, 2023, 4:23 PM Reply Quote 0
    • M
      michmoor LAYER 8 Rebel Alliance @michmoor
      last edited by Apr 10, 2023, 4:23 PM

      @michmoor This was solved on my end. Was an issue with the backend server domain-name vs. hostname configured.

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received