# Backend using https on different port

**URL:** <https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213>\
**Category:** Help!\
**Created:** [November 9, 2018, 6:39pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213 "2018-11-09T18:39:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gytrdun](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/gytrdun/32/674_2.png) [@gytrdun](https://discourse.haproxy.org/u/gytrdun)\
**Post date:** [November 9, 2018, 6:39pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213/1 "2018-11-09T18:39:57Z")

</div>

Hello, we have backend servers that responds to something like

[https://servername1.domain.com:9900/someurl](https://servername1.domain.com:9900/someurl)  
[https://servername2.domain.com:9900/someurl](https://servername2.domain.com:9900/someurl)

I’m having a hard time figuring out how to get it to work. I’d like to hit [http://haproxy.domain.com/someurl](http://haproxy.domain.com/someurl), or even [http://haproxy.domain.com:9900/someurl](http://haproxy.domain.com:9900/someurl).

I’ve tried every iteration that I can find in the haproxy.conf, but nothing seems to work.

This is my current config, which I know is incorrect, but just to let you know where I’m at:

frontend localnodes  
bind \*:80  
bind \*:9900  
option tcplog  
mode tcp  
default\_backend nodes

backend nodes  
mode tcp  
balance roundrobin  
option tcp-check  
server servername1 12.12.12.12:9900 check

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [November 9, 2018, 6:59pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213/2 "2018-11-09T18:59:36Z")

</div>

I don’t see anything wrong with your configuration, I assume the problem is elsewhere.

First of all: what’s happening when you do the above? Any error messages from browser/curl?

Also, what’s the output from the equivilant of:

`curl -v http://12.12.12.12:9900/someurl`

Your backend server may require a particular Host header for example.

---

<div class="post-metadata">

**Author:** ![gytrdun](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/gytrdun/32/674_2.png) [@gytrdun](https://discourse.haproxy.org/u/gytrdun)\
**Post date:** [November 9, 2018, 7:56pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213/3 "2018-11-09T19:56:19Z")

</div>

I can hit my backend servers through a browser just fine. On the HAProxy machine, I can curl successfully to the backend servers as well and get the expected response. I the configuration I put above, there was no browser output. I’ve changed it to the following:

frontend localnodes  
bind 192.168.231.236:9900  
mode tcp  
default\_backend nodes

backend nodes  
server servername1 12.12.12.12:9900 check ssl verify none

And I get 502 Bad Gateway  
The server returned an invalid or incomplete response.

I’d like to leave certificates out of haproxy, and just have it pass everything to the backend. I apologize in advance for switching the config around, just trying anything at this point 🙂

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [November 9, 2018, 8:31pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213/4 "2018-11-09T20:31:51Z")

</div>

Is the 9900 port on your backend server HTTPS?

> [@gytrdun](#):
>
> On the HAProxy machine, I can curl successfully to the backend servers as well and get the expected response.

What this test was supposed to show is whether you can curl to your backend server by using the ip address only, instead of the hostname, to check whether or not the backend server needs Host header or SNI.

Does it work when you curl with the IP address only?

Please remove the check keyword from the server configuration for now; you don’t need another variable in there if nothing works in the first place.

I also suggest you logging in haproxy.

---

<div class="post-metadata">

**Author:** ![gytrdun](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/gytrdun/32/674_2.png) [@gytrdun](https://discourse.haproxy.org/u/gytrdun)\
**Post date:** [November 9, 2018, 8:45pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213/5 "2018-11-09T20:45:32Z")

</div>

> [@lukastribus](#):
>
> What this test was supposed to show is whether you can curl to your backend server by using the ip address only, instead of the hostname, to check whether or not the backend server needs Host header or SNI.

Understood. I’m able curl to the back side machine via both ip address and hostname, as well as fqdn

> [@lukastribus](#):
>
> Please remove the check keyword from the server configuration for now; you don’t need another variable in there if nothing works in the first place.

Done, no change.

> [@lukastribus](#):
>
> I also suggest you logging in haproxy.

I’m working on that now. Thank you for the assistance!

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [November 9, 2018, 11:36pm UTC](https://discourse.haproxy.org/t/backend-using-https-on-different-port/3213/6 "2018-11-09T23:36:17Z")

</div>

This may be a SSL issue at this point. Can you provide the output of `haproxy -vv` as well as your default/global configuration? The (successful) `curl -v` output regarding the SSL handshake would help as well as ultimately a tcpdump capture between haproxy and the backend server (something like `tcpdump -pns0 -w ssl.cap port 9900`).
