# Accessing Client IP in Backend Server is SSLPassthrough mode

**URL:** <https://discourse.haproxy.org/t/accessing-client-ip-in-backend-server-is-sslpassthrough-mode/4089>\
**Category:** Help!\
**Created:** [July 24, 2019, 11:40am UTC](https://discourse.haproxy.org/t/accessing-client-ip-in-backend-server-is-sslpassthrough-mode/4089 "2019-07-24T11:40:11Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![shivharsh](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/shivharsh/32/388_2.png) [@shivharsh](https://discourse.haproxy.org/u/shivharsh)\
**Post date:** [July 25, 2019, 6:23pm UTC](https://discourse.haproxy.org/t/accessing-client-ip-in-backend-server-is-sslpassthrough-mode/4089/2 "2019-07-25T18:23:46Z")

</div>

Hello Sisir,

For SSLPassthrough mode, HAProxy is configured to use TCP protocol rather than HTTP and therefore looses the ability to use the `X-Forwarded-*` headers.  
The solution to this problem is to make use of PROXY Protocol. You need to enable PROXY protocol by using send-proxy keyword in your HAProxy backend configuration.

> server srv1 Y.Y.Y.Y:7654 send-proxy

You may refer to the following post for further details: [HAProxy to retain client IP - #3 by Thoufiq](https://discourse.haproxy.org/t/haproxy-to-retain-client-ip/3828/3)

Thanks,  
Shivharsh

---

_[View the full topic](https://discourse.haproxy.org/t/accessing-client-ip-in-backend-server-is-sslpassthrough-mode/4089)._
