Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HAProxy forwardfor

    Scheduled Pinned Locked Moved Cache/Proxy
    6 Posts 2 Posters 379 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      varazir
      last edited by

      Hi,

      I'm trying to setup Add an X-Forwarded-For header.

      Here is my haproxy.cfg

      It's for the Domoticz_ipvANY backend but I want it for more later.

      When I check my logs in Domoticz I only see pfSense IP connecting.

      TIA

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @varazir
        last edited by

        @varazir
        "Add an X-Forwarded-For header" does, what its name implies. It adds a http header in traffic sent to the backen, which contains the real client source IP.

        To get benefit of this, you have to configure your backend server to read and log the content of the X-Forwarded-For header. It might not do this out of the box.

        V 2 Replies Last reply Reply Quote 1
        • V
          varazir @viragomann
          last edited by

          @viragomann redid the HAproxy rules and now it's working.

          1 Reply Last reply Reply Quote 0
          • V
            varazir @viragomann
            last edited by

            @viragomann Hmm, looks like it's not working.

            I did a tcpdump on the backend server and the X-Forwarded-For are not set as far as I can see in wireshark.

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @varazir
              last edited by

              @varazir
              You can see the http headers in the capture?

              V 1 Reply Last reply Reply Quote 0
              • V
                varazir @viragomann
                last edited by

                @viragomann said in HAProxy forwardfor:

                @varazir
                You can see the http headers in the capture?

                yes, strange is that it's only for Authelia I don't get the header set. I think I'm going to remove it.
                Using wireguard to connect to my home network.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.