Can pfsense detect requests and routing to set hostname
- 
 I would set the destination on the WAN firewall rule to something that contains only the IPs you expect HAProxy to receive connections on. So maybe an alias with those IPs in it or set it to the WAN subnet if the VIPs are inside that. 
- 
 You man inside Firewall / Rules / WAN where i create one rule with status PASS 
 Protocol: TCP/UDP
 Source Address: ! WAN address
 Source Ports: Any
 Dest. Address: ! Local address
 Dest. Ports: Any
 And enable Log packets that are handled by this ruleI plan to test and create an inside Firewall / Aliases / Ports list of only ports that who lab user or service can use. 
- 
 @sysbitnet said in Can pfsense detect requests and routing to set hostname: Dest. Address: ! Local address I mean that is too wide a match. It would match a lot of traffic that shouldn't be allowed. Though I don't know exactly what 'Local' is there. The only traffic you should allow into the WAN should have a destination of the IPs HAProxy is listening on. So at most the WAN address and/or the VIPs on the WAN. And yes the destination ports should probably be an alias of 443 and 80 only. 
- 
 In the lab case, i have only one public IP but if I understand your suggestion. I plan to see you for testing on Firewall / Aliases / IP Name: web1 
 IP: 192.168.100.1Name: web2 
 IP: 192.168.100.2And create an inside Firewall / Aliases / Ports list of only ports that who lab user or service can use like. Name: WWW 
 Ports: 80, 443And to inside Firewall / Rules / WAN where i create a rule with the status PASS 
 Protocol: TCP/UDP
 Source Address: ! WAN address
 Source Ports: Any
 Dest. Address: web1
 Dest. Ports: WWW
 And enable Log packets that are handled by this rule
- 
 I just tried to add like new service wowza and when visited VM3 with http://192.168.100.3:8088 in the local host i saw see login page, but when i try to access wowza with a set domain name like http://wowza.domain.com:8088 i get this result 503 Service Unavailable 
 No server is available to handle this request.when i check with the LISTEN port like this root@dev:~# lsof -i -P -n | grep LISTEN systemd 1 root 40u IPv6 8353844 0t0 TCP *:22 (LISTEN) systemd-r 96 systemd-resolve 14u IPv4 8354932 0t0 TCP 127.0.0.53:53 (LISTEN) java 123 root 25u IPv4 8347558 0t0 TCP *:8088 (LISTEN) java 287 root 8u IPv4 8355219 0t0 TCP *:41183 (LISTEN) java 287 root 164u IPv4 8353064 0t0 TCP *:8087 (LISTEN) java 287 root 172u IPv4 8358134 0t0 TCP *:8083 (LISTEN) java 287 root 187u IPv4 8358172 0t0 TCP *:1935 (LISTEN) java 287 root 191u IPv4 8358176 0t0 TCP *:8086 (LISTEN) master 358 root 13u IPv4 8347603 0t0 TCP 127.0.0.1:25 (LISTEN) master 358 root 14u IPv6 8347604 0t0 TCP [::1]:25 (LISTEN)I created the same as i did earlier for port 80 and port 443 but is not working. I know i need to add SSL, but as i write this is lab testing, not production. 
- 
 @sysbitnet said in Can pfsense detect requests and routing to set hostname: Dest. Address: web1 That destination on the WAN would be the WAN address if you don't have any VIPs on it. web1 is an internal IP that could never be reached by an external host. 
- 
 Do you maybe know what can be a problem why i get 503 Service Unavailable 
 No server is available to handle this request.When i try to use another service like Wowza? Port 80,443 its working perfect, but when i wont to add on the same case other port or services i get the same error 503 Service Unavailable 
 No server is available to handle this request.Thank you 
- 
 I don't know what Wowza is. What exactly have you added? How are you testing it? What do you expect to see? 
- 
 Wowza is a video platform with industry-leading technology that delivers quality live and VOD streaming with integrated CMS, analytics, and more. But i have the same problem when i try another service, like access on proxmox or any other service who requests another port number but is not port 443 and port 80 Any time i get 
 503 Service Unavailable
 No server is available to handle this request.
- 
 Sounds like HAProxy it not configured to use that port so it just returns that 503 error. 
- 
 @stephenw10 
 I agree with you.How can testing what is the problem only leave this service, for example, i used to test proxmox. Inside Services / HAProxy / Backend Name: PM_8006 
 Mode: active
 Name: pm
 Forward to: Address+Port
 Address: 192.168.100.3
 Port: 8006
 Encrypt(SSL): yes
 SSL checks: yes
 And in the Health check method set: basicHow i configure On the Frontend part. Services / HAProxy / Frontend 
 Name: PM_Front
 External address
 Listen address: WAN address (IPv4)
 Port: 8006
 SSL Offloading: yesIn Access Control lists inside the same 
 Name: pm
 Expression: Host matches
 CS: empty
 Note: empty
 Value: pm.domain.comIn part Actions inside the same Action Use Backend the name that i set on PM_8006 
 Condition acl names: the same name that i set in Access Control lists pmAnd inside the same Additional certificates select SSL Offloading what i on System / Certificates / Certificates The same certificate and added inside proxmox, because is letsencrypt wildcard certificate And when i try to visit https://pm.domain.com:8006/ the result is like this below message. 503 Service Unavailable 
 No server is available to handle this request.
- 
 What do you logged? Do you see states created on port 8006? For both front and back end? 
- 
 This post is deleted!
- 
 I do the same as how i explained in my last post. I tried many other services that request custom ports and got the same. 503 Service Unavailable 
 No server is available to handle this request.
- 
 So do you see states created? 
- 
 Yes, I set. When i do this just for testing 
  
 How can i see if i correctly configured and tried to access it, this is working perfectly.IP_ProxMox is set localhost IP set inside Firewall / Aliases / IP When i disable this Port Forward and now testing to login again like https://pm.domain.com:8006 i get this result 503 Service Unavailable 
 No server is available to handle this request.If i have a set like this inside HAProxy @sysbitnet said in Can pfsense detect requests and routing to set hostname: Inside Services / HAProxy / Backend Name: PM_8006 
 Mode: active
 Name: pm
 Forward to: Address+Port
 Address: 192.168.100.3
 Port: 8006
 Encrypt(SSL): yes
 SSL checks: yes
 And in the Health check method set: basicHow i configure On the Frontend part. Services / HAProxy / Frontend 
 Name: PM_Front
 External address
 Listen address: WAN address (IPv4)
 Port: 8006
 SSL Offloading: yesIn Access Control lists inside the same 
 Name: pm
 Expression: Host matches
 CS: empty
 Note: empty
 Value: pm.domain.comIn part Actions inside the same Action Use Backend the name that i set on PM_8006 
 Condition acl names: the same name that i set in Access Control lists pmAnd inside the same Additional certificates select SSL Offloading what i on System / Certificates / Certificates The same certificate and added inside proxmox, because is letsencrypt wildcard certificate And when i try to visit https://pm.domain.com:8006/ the result is like this below message. 503 Service Unavailable 
 No server is available to handle this request.
- 
 But do you see states on port 8006 in Diag > States? 
- 
 @stephenw10 said in Can pfsense detect requests and routing to set hostname: But do you see states on port 8006 in Diag > States? If you mean on Diagnostics / States / States yes this is what i get as a result.  
- 
 Ok. So what is the LAB interface? What are the IPs there? I expect to see a port 8006 state on WAN whilst you're testing. 
- 
 @stephenw10 said in Can pfsense detect requests and routing to set hostname: Ok. So what is the LAB interface? What are the IPs there? I expect to see a port 8006 state on WAN whilst you're testing. LAB interface is a local private network, 192.168.100.0./24 
 
 
 
 

