• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

HA Proxy with multiple Public IP's

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 2 Posters 2.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mrjoli021
    last edited by Nov 22, 2023, 8:16 PM

    Hello,

    I have a private web_server running on port 80. I would like to have pfsense terminate the ssl cert and then redirect traffic to the internal server. I have a /27 configured on my firewall and I would like to use one of my unused IP's for this. I am using the video below as a reference.

    https://forums.serverbuilds.net/t/guide-reverse-proxy-via-haproxy-acme-on-pfsense/3513

    When I configure the HAProxy frontend. I am doing the frontend section. I called the name "https_shared" I am setting "external address -> Listen address" to custom addrress and then putting my public IP there and setting the port to 443 with SSL offloading. When I attempt to save the settings, I get the following error message. If I select the WAN Address, it works, but I dont want to use that IP.

    "
    [NOTICE] (62594) : haproxy version is 2.8.3-86e043a
    [NOTICE] (62594) : path to executable is /usr/local/sbin/haproxy
    [ALERT] (62594) : Binding [/var/etc/haproxy/haproxy.cfg:27] for frontend https_shared-merged: cannot bind socket (Can't assign requested address) for [1.2.3.19:443]
    [ALERT] (62594) : [/usr/local/sbin/haproxy.main()] Some protocols failed to start their listeners! Exiting.
    "

    Any suggestions?

    Thanks,

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Nov 22, 2023, 8:53 PM

      Have you added an IPAlias VIP for that IP address on the WAN?

      M 1 Reply Last reply Nov 22, 2023, 10:25 PM Reply Quote 0
      • M
        mrjoli021 @stephenw10
        last edited by Nov 22, 2023, 10:25 PM

        @stephenw10

        Yes. I have tried it with that as well and getting the same error message. I saw on the bottom a note that said that I had to do that. I added that ip as an alias and the same thing.

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Nov 23, 2023, 1:58 AM

          Is the VIP valid? Can you ping out from it in Diag > Ping?

          1 Reply Last reply Reply Quote 0
          • M
            mrjoli021
            last edited by Nov 23, 2023, 6:15 PM

            Found my issue. I had the wrong IP set in the backend.

            thanks,

            1 Reply Last reply Reply Quote 1
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received