<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Inbound Failover for HTTPS]]></title><description><![CDATA[<p dir="auto">Hi Folks,</p>
<p dir="auto">is it possible to have a failover for https requests on pfsense (2.0-RELEASE (amd64)? Which tool should i use?</p>
<p dir="auto">I set up the load balancer (which exists by default) on pfsense but the problem is that the https requests are hopping from web1 to web2 and vice versa. Even with the sticky connection option is behaving the same :/</p>
<p dir="auto">I tried HAproxy but there i had another problem. When i configure the haproxy for http then the http request is going to web1 (or web2) and it's being redirected to https (as the servers are configured to redirect http to https) and the client receives an SSL Connection Error. If i send directly an https request then i have the same result.<br />
When I configure the haproxy for https then the requests are not even reaching one of the 2 servers, and i can also not access the stats.<br />
for configuring the haproxy i followed this http://forum.pfsense.org/index.php/topic,21748.0.html and this http://conheotiensinh.blogspot.com/2011/12/config-haproxy-with-pfsense-version-201.html</p>
<p dir="auto">I want to set a failover for my webservers. I want all HTTPS requests to go to web1 and in case web1 is down then the traffic to be (re)directed to web2. is that possible with pfSense?</p>
<p dir="auto">thnx in advance</p>
]]></description><link>https://forum.netgate.com/topic/42780/inbound-failover-for-https</link><generator>RSS for Node</generator><lastBuildDate>Tue, 10 Mar 2026 06:26:54 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/42780.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 09 Mar 2012 14:26:32 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Tue, 13 Mar 2012 22:29:04 GMT]]></title><description><![CDATA[<p dir="auto">thnx once again!!</p>
<p dir="auto">i published haproxy in an internal ip address as well for the stats, it was not necessary to assign any backend.</p>
<p dir="auto">best regards</p>
]]></description><link>https://forum.netgate.com/post/324879</link><guid isPermaLink="true">https://forum.netgate.com/post/324879</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Tue, 13 Mar 2012 22:29:04 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 23:36:04 GMT]]></title><description><![CDATA[<p dir="auto">Publish another haproxy server config with internal address, stats enabled and assign the http backend just to get stats working.</p>
]]></description><link>https://forum.netgate.com/post/324671</link><guid isPermaLink="true">https://forum.netgate.com/post/324671</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 23:36:04 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 22:44:24 GMT]]></title><description><![CDATA[<p dir="auto">hey marcelloc,</p>
<p dir="auto">thanks a lot man!! i removed the "server cookies" from the backends and also "advanced pass thru" from the frontends and seems to be working great so far!! :)</p>
<p dir="auto">btw, as i don't want the stats to be accessible from internet.. is it possible to make the stats accessible just from VPN connection in some other internal IP address? or i should just disable the stats?</p>
]]></description><link>https://forum.netgate.com/post/324664</link><guid isPermaLink="true">https://forum.netgate.com/post/324664</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 22:44:24 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 19:06:40 GMT]]></title><description><![CDATA[<p dir="auto">On backends I do not fill up <em>Advanced pass thru</em> and do not set cookies on Servers.</p>
<p dir="auto">The other settings looks similar here.</p>
<p dir="auto">Enable stats and try to see what happens.</p>
]]></description><link>https://forum.netgate.com/post/324620</link><guid isPermaLink="true">https://forum.netgate.com/post/324620</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 19:06:40 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 15:55:19 GMT]]></title><description><![CDATA[<p dir="auto">i removed haproxy and installed haproxy legacy and then i configured it again.<br />
the results are same as before :/<br />
here is my configuration…</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/frontend1.png" alt="frontend1.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/frontend1.png_thumb" alt="frontend1.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/frontend2.png" alt="frontend2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/frontend2.png_thumb" alt="frontend2.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/frontend3.png" alt="frontend3.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/frontend3.png_thumb" alt="frontend3.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/backend1.png" alt="backend1.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/backend1.png_thumb" alt="backend1.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/backend2.png" alt="backend2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/backend2.png_thumb" alt="backend2.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/324593</link><guid isPermaLink="true">https://forum.netgate.com/post/324593</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 15:55:19 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 15:38:36 GMT]]></title><description><![CDATA[<p dir="auto">Can you try this setup with legacy package?</p>
<p dir="auto">I'm using it, so it will be easier to me to compare my setup with yours.</p>
<p dir="auto">This week I`ll rename haproxy-lagacy to haproxy-full as it has more options then current 1.2 package.</p>
<p dir="auto">Both(1.2 and 1.0) use the same 1.4.19 version of haproxy.</p>
<p dir="auto">att,<br />
Marcello Coutinho</p>
]]></description><link>https://forum.netgate.com/post/324586</link><guid isPermaLink="true">https://forum.netgate.com/post/324586</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 15:38:36 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 15:32:59 GMT]]></title><description><![CDATA[<p dir="auto">here it's my configuration of haproxy…what am i doing wrong ???</p>
<p dir="auto">the virtual IP is on the wan interface and it's CARP.<br />
when the client is sending https request is not getting any answer<br />
with http requests is going to pfsense web interface.</p>
<p dir="auto">thnx once again man!!</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/listener1.png" alt="listener1.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/listener1.png_thumb" alt="listener1.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/listener2.png" alt="listener2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/listener2.png_thumb" alt="listener2.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/listener3.png" alt="listener3.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/listener3.png_thumb" alt="listener3.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pool1.png" alt="pool1.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pool1.png_thumb" alt="pool1.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pool2.png" alt="pool2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pool2.png_thumb" alt="pool2.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/324585</link><guid isPermaLink="true">https://forum.netgate.com/post/324585</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 15:32:59 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 15:08:27 GMT]]></title><description><![CDATA[<p dir="auto">Can you screenshot your haproxy config?</p>
]]></description><link>https://forum.netgate.com/post/324579</link><guid isPermaLink="true">https://forum.netgate.com/post/324579</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 15:08:27 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 15:01:38 GMT]]></title><description><![CDATA[<p dir="auto">haproxy doesn't seem to be working for me :/ it's not even forwarding the requests to web1 or web2, i don't know what i am doing wrong there  :-[</p>
<p dir="auto">furthermore, after some tries to edit the configuration for the frontend is accepting the changes but is not updating the configuration, it seems like there is a bug in haproxy legacy (at least 2.0-RELEASE (amd64)).</p>
<p dir="auto">as for the load balancer what i noticed is that when i take web1 down i can see from the pool tab that web1 is down (red) but on the virtual server tab it keeps "targeting" (forwarding) the requests to web1, which means that the virtual server is not refreshing the status right after the pool.</p>
]]></description><link>https://forum.netgate.com/post/324577</link><guid isPermaLink="true">https://forum.netgate.com/post/324577</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 15:01:38 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 13:07:11 GMT]]></title><description><![CDATA[<p dir="auto">I enable stats on internal pools only. Any stat page show stats for all pools.</p>
]]></description><link>https://forum.netgate.com/post/324561</link><guid isPermaLink="true">https://forum.netgate.com/post/324561</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 13:07:11 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 13:02:53 GMT]]></title><description><![CDATA[<p dir="auto">yeah i will give it a try with haproxy (legacy) again and see if it can work.</p>
<p dir="auto">when i tried i used a virtual carp IP (internet IP) and there i could also access the stats, but i didn't like that the stats were accessible from internet.<br />
is it possible to access the stats (and setup haproxy) in another IP and not in the external IP of haproxy?</p>
]]></description><link>https://forum.netgate.com/post/324560</link><guid isPermaLink="true">https://forum.netgate.com/post/324560</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 13:02:53 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 12:52:53 GMT]]></title><description><![CDATA[<p dir="auto">Well, I use haproxy for https as I told you with no issues.</p>
<p dir="auto">Can you try haproxy again using source as balance method, one pool for http and another pool for https?</p>
]]></description><link>https://forum.netgate.com/post/324556</link><guid isPermaLink="true">https://forum.netgate.com/post/324556</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 12:52:53 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 12:48:38 GMT]]></title><description><![CDATA[<p dir="auto">thnx for your time and help marcelloc</p>
<p dir="auto">yes i tried them,<br />
the manual failover cannot do what i need, because i want the traffic to be forwarded automatically to web2 when web1 is down.<br />
and haproxy didn't look to work for https traffic, thus i chose to stay at loadbalancer solution, just i need to improve the time that it takes for forwarding the requests to web2 when web1 is down.<br />
isn't it there a way to make it faster?<br />
the point is that the load balancer is recognizing very fast that the web1 is down, is just not changing the forwarding to web2.</p>
]]></description><link>https://forum.netgate.com/post/324552</link><guid isPermaLink="true">https://forum.netgate.com/post/324552</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 12:48:38 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 12:39:24 GMT]]></title><description><![CDATA[<p dir="auto">Did you tried the manual failover or haproxy before this fallback pool?</p>
]]></description><link>https://forum.netgate.com/post/324550</link><guid isPermaLink="true">https://forum.netgate.com/post/324550</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 12:39:24 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 12:34:28 GMT]]></title><description><![CDATA[<p dir="auto">from the client side i cannot access the web (This webpage is not available) and on the FW i can see that the requests are going to web1 even if the load balancer recognizes that it is down. After 2 or 3 minutes is redirecting the traffic to web2.</p>
]]></description><link>https://forum.netgate.com/post/324548</link><guid isPermaLink="true">https://forum.netgate.com/post/324548</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 12:34:28 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 12:23:14 GMT]]></title><description><![CDATA[<p dir="auto">Are you getting errors from client access or just seeing some traffic going(heath status check from firewall for example) to down server?</p>
]]></description><link>https://forum.netgate.com/post/324544</link><guid isPermaLink="true">https://forum.netgate.com/post/324544</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Mon, 12 Mar 2012 12:23:14 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Mon, 12 Mar 2012 12:14:39 GMT]]></title><description><![CDATA[<p dir="auto">i tried it and it seems that it's working!</p>
<p dir="auto">however, the redirection is very slow,</p>
<p dir="auto">when i take apache down on web1 then from loadbalncer status i can see that the pool with the web1 is down and the pool with the web2 is up (green). however, the loadbalancer is still forwarding the http(s) requests to web1 for some minutes, and then after 2,3 minutes it switching to web2  ???</p>
<p dir="auto">is there a way to improve this and make it faster so it will not take so long?</p>
<p dir="auto">thnx</p>
]]></description><link>https://forum.netgate.com/post/324542</link><guid isPermaLink="true">https://forum.netgate.com/post/324542</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Mon, 12 Mar 2012 12:14:39 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Fri, 09 Mar 2012 16:28:13 GMT]]></title><description><![CDATA[<p dir="auto">I think i got what you mean :)<br />
hope that will work  8)</p>
<p dir="auto">thnx a lot!!</p>
]]></description><link>https://forum.netgate.com/post/324285</link><guid isPermaLink="true">https://forum.netgate.com/post/324285</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Fri, 09 Mar 2012 16:28:13 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Fri, 09 Mar 2012 16:14:52 GMT]]></title><description><![CDATA[<p dir="auto">thnx for the fast reply man!!</p>
<p dir="auto">how can i create the Fall Back Pool??<br />
i am creating a pool with the just web1 on it and then a second pool with just the web2? is this what u mean?</p>
]]></description><link>https://forum.netgate.com/post/324281</link><guid isPermaLink="true">https://forum.netgate.com/post/324281</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Fri, 09 Mar 2012 16:14:52 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Fri, 09 Mar 2012 16:02:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/skipper">@<bdi>skipper</bdi></a>:</p>
<blockquote>
<p dir="auto">how can i use pfsense loadbalancer for failover, there is just loadbalancing and manual failover mode. I want all requests to go to web1 and just if web1 is down then the https requests go to web2. is that possible? i followed this howto http://www.howtoforge.com/how-to-use-pfsense-to-load-balance-your-web-servers</p>
</blockquote>
<p dir="auto">If you do not want to use manual failover, you can create a pool for each server and setup  Virtual Server with <strong>Virtual Server Pool</strong> for the first server and <strong>Fall Back Pool</strong> for the second</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/skipper">@<bdi>skipper</bdi></a>:</p>
<blockquote>
<p dir="auto">i tried with haproxy (haproxy-legacy 1.4.19 pkg v 1.0) following this howto http://conheotiensinh.blogspot.com/2011/12/config-haproxy-with-pfsense-version-201.html but since my webservers are redirecting http to https i was getting an ssl error.</p>
</blockquote>
<p dir="auto">If you have both http and https going to the same server, this should be transparent.<br />
Did you selected <strong>Source</strong> as a balance method on your haproxy frontends?</p>
]]></description><link>https://forum.netgate.com/post/324277</link><guid isPermaLink="true">https://forum.netgate.com/post/324277</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Fri, 09 Mar 2012 16:02:32 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Fri, 09 Mar 2012 15:10:52 GMT]]></title><description><![CDATA[<p dir="auto">hi marcelloc,</p>
<p dir="auto">how can i use pfsense loadbalancer for failover, there is just loadbalancing and manual failover mode. I want all requests to go to web1 and just if web1 is down then the https requests go to web2. is that possible? i followed this howto http://www.howtoforge.com/how-to-use-pfsense-to-load-balance-your-web-servers</p>
<p dir="auto">i tried with haproxy (haproxy-legacy 1.4.19 pkg v 1.0) following this howto http://conheotiensinh.blogspot.com/2011/12/config-haproxy-with-pfsense-version-201.html but since my webservers are redirecting http to https i was getting an ssl error.</p>
]]></description><link>https://forum.netgate.com/post/324265</link><guid isPermaLink="true">https://forum.netgate.com/post/324265</guid><dc:creator><![CDATA[skipper]]></dc:creator><pubDate>Fri, 09 Mar 2012 15:10:52 GMT</pubDate></item><item><title><![CDATA[Reply to Inbound Failover for HTTPS on Fri, 09 Mar 2012 14:33:21 GMT]]></title><description><![CDATA[<p dir="auto">I use haproxy for https failover without issues.</p>
<p dir="auto">what version of haproxy are you using?</p>
<p dir="auto">The pfsense loadbalancer(relayd) is also usefull for https failover.</p>
]]></description><link>https://forum.netgate.com/post/324256</link><guid isPermaLink="true">https://forum.netgate.com/post/324256</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Fri, 09 Mar 2012 14:33:21 GMT</pubDate></item></channel></rss>