# Bind 443 to multiple backends based on dummy paths

**URL:** <https://discourse.haproxy.org/t/bind-443-to-multiple-backends-based-on-dummy-paths/3046>\
**Category:** Help!\
**Created:** [September 28, 2018, 3:48am UTC](https://discourse.haproxy.org/t/bind-443-to-multiple-backends-based-on-dummy-paths/3046 "2018-09-28T03:48:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinosauriecito](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@dinosauriecito](https://discourse.haproxy.org/u/dinosauriecito)\
**Post date:** [September 28, 2018, 3:48am UTC](https://discourse.haproxy.org/t/bind-443-to-multiple-backends-based-on-dummy-paths/3046/1 "2018-09-28T03:48:17Z")

</div>

Hi! I am new to the forum and after learning and searching a lot in Google is I come up here because I wasn’t able to achive the challenge I am going to explain. Before I start, I started to use Haproxy a few months ago and even though I read a lot about proxy pass, forward and redirect, I think I still don’t understand them enough so I will explain with a diagram I made for the case and my words:

 ![haproxy_forum](https://us1.discourse-cdn.com/flex016/uploads/haproxy/original/1X/d72b4434243528f8153e8816c7905d5c7518f36d.png)

So the thing is I want to connect to my home several services(cameras, nextcloud and others) through only port 443 by diferentiating them through dummy paths (I mean by dummy paths, non existing paths).

The reason for this is that lot of outside internet conections have strong firewalls and port 443 is the only port I can use to connect to my home network. I have Openvpn but I can’t ask everyone to use my vpn to connect to a service.

So after some work, I come up with something that seems is on the way but still lacks something:

> frontend rules\_443\_ssl2  
> bind \*:443 ssl crt my\_cert.pem  
> mode tcp  
> tcp-request inspect-delay 3s  
> tcp-request content accept if { req.ssl\_hello\_type 1 }
> 
> ```
> use_backend cam1 if { url_beg /cam1 }
> use_backend cam2 if { url_beg /cam2 }
> use_backend nextcloud if { url_beg /nextcloud }
> default_backend tcp_ovpn
> 
> ```
> 
> backend cam1  
> mode http  
> option forwardfor  
> option http-server-close  
> http-request set-header X-Forwarded-Port %[dst\_port]  
> http-request add-header X-Forwarded-Proto https if { ssl\_fc }  
> http-request set-path %[path,regsub(^/cam1/?,/)] if { path /cam3 } or { path\_beg /cam1/ }  
> server ipcam 192.168.0.147:8081 check fall 3 rise 2 maxconn 50
> 
> backend cam2  
> (similar to 1)
> 
> backend nextcloud  
> mode http  
> http-request set-path %[path,regsub(^/nextcloud/?,/)] if { url\_beg /nextcloud } or { path\_beg /nextcloud }  
> #reqrep ^([^\]_\ /)nextcloud[/]?(._) \1\ \2  
> server nextcloud 127.0.0.1:8084 ssl verify none
> 
> backend tcp\_ovpn  
> mode tcp  
> option ssl-hello-chk  
> server ovpn 127.0.0.1:1194 maxconn 50

So when I test it this is what happens:

1. From my computer’s web browser I type: https://home\_IP/cam1
2. I get: https://home\_IP/main.htm  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/haproxy/original/1X/4b8c290020bb7d5d9a6515cd1c2a3328a552a26b.png)

When I see haproxy log I can see that 1) hits the correct backend(camera 1) but when the backend camera redirects me to its login pagem It doesn’t add the “cam1/login.htm” dummy path and instead sends my directly to “login.htm” and thus I end up in the Openvpn backend which is the default.

So If I type: https://home\_IP/cam1/main.htm I reach the camera login but if I login I still get this error.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 2, 2018, 6:58pm UTC](https://discourse.haproxy.org/t/bind-443-to-multiple-backends-based-on-dummy-paths/3046/2 "2018-10-02T18:58:32Z")

</div>

From a quick glance at this configuration there are a number of things wrong with it:

- you cannot terminate ssl and then forward it to OpenVPN. OpenVPN needs to handle crypto on it’s own, you are interferening with it, and it will never work that way
- you cannot access HTTP field in a frontend that is in TCP mode

I would also strongly suggest that you don’t fiddle with those paths (/nextcloud, /cam3, /cam2, etc). It is extremely error prone, and your backends application may refer to absolute paths, which then fail, etc.

You need a layered approach, where you don’t terminate SSL on your primary frontend, you use SNI to differentiate between different backend applications (with different hostnames) and default\_backend to openvpn.

Check this post for an example of how to use a 2 layered approach:

> [@How to set ssl verify client for specific domain name](https://discourse.haproxy.org/t/how-to-set-ssl-verify-client-for-specific-domain-name/1489/3):
>
> There is no simple way to do this, unfortunately. Use a TCP frontend withouth SSL termination, SNI route to different backends that recirculate to traffic to dedicated SSL frontends with different configurations. Something like: frontend port443 bind :443 tcp-request inspect-delay 5s tcp-request content accept if { req\_ssl\_hello\_type 1 } use\_backend recir\_clientcertenabled if { req\_ssl\_sni -i test1.demo.com } default\_backend recir\_default backend recir\_clientcertenabled …

---

<div class="post-metadata">

**Author:** ![dinosauriecito](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@dinosauriecito](https://discourse.haproxy.org/u/dinosauriecito)\
**Post date:** [October 9, 2018, 3:02am UTC](https://discourse.haproxy.org/t/bind-443-to-multiple-backends-based-on-dummy-paths/3046/3 "2018-10-09T03:02:43Z")

</div>

Thank you Lukas! I really wanted the path solution but since [duckdns.org](http://duckdns.org) allows me to have multiple hostnames your solution worked out.

For anyone looking for the final solution, this is a working substract:

> ##########################
> 
> # Host redirection with SNI
> 
> ##########################  
> frontend rules\_443\_ssl2  
> bind-process 2-4  
> bind \*:443 tfo process 2  
> bind \*:443 tfo process 3  
> bind \*:443 tfo process 4  
> mode tcp  
> option tcplog  
> tcp-request inspect-delay 5s  
> tcp-request content accept if { req.ssl\_hello\_type 1 }  
> use\_backend recir\_client1 if { req\_ssl\_sni -i my\_host1.duckdns.org }  
> use\_backend recir\_client2 if { req\_ssl\_sni -i my\_host2.duckdns.org }  
> use\_backend recir\_client3 if { req\_ssl\_sni -i my\_host3.duckdns.org }  
> use\_backend recir\_client4 if { req\_ssl\_sni -i my\_host4.duckdns.org }  
> use\_backend recir\_client5 if { req\_ssl\_sni -i my\_other\_host }  
> use\_backend recir\_client6 if { req\_ssl\_sni -i my\_other\_host2 }  
> default\_backend openvpn\_dest\_8070
> 
> #Intermediate backend to frontend(1:apexis, 2:foscamhttp, 3:tplink8080, 4:motion, 5:tplink8092, 6:Openvpn)  
> backend recir\_client1  
> server loopback-for-tls abns@haproxy-clt1 send-proxy-v2  
> backend recir\_client2  
> server loopback-for-tls abns@haproxy-clt2 send-proxy-v2  
> backend recir\_client3  
> server loopback-for-tls abns@haproxy-clt3 send-proxy-v2  
> backend recir\_client4  
> server loopback-for-tls abns@haproxy-clt4 send-proxy-v2  
> backend recir\_client5  
> server loopback-for-tls abns@haproxy-clt5 send-proxy-v2  
> backend recir\_client6  
> server loopback-for-tls abns@haproxy-clt6 send-proxy-v2  
> ###########
> 
> # OPENVPN
> 
> ###########  
> frontend openvpn\_in\_443\_8070  
> bind \*:8071 bind abns@haproxy-clt6 accept-proxy tfo  
> option tcplog  
> mode tcp  
> option tcp-smart-accept  
> default\_backend openvpn\_dest\_8070
> 
> backend openvpn\_dest\_8070  
> mode tcp  
> #option ssl-hello-chk  
> option tcp-smart-connect  
> server ovpn 127.0.0.1:8070 maxconn 50
> 
> ############
> 
> # CAMERA1
> 
> ############  
> frontend foscam\_in\_8072  
> bind-process 2-4  
> bind \*:8097 tfo ssl crt /etc/ssl/certs\_self/ec\_concatenated\_prime256v1.pem crt /etc/ssl/certs\_self/ec\_concatenated\_secp348r1.pem crt /etc/ssl/certs\_self/ec\_concatenated\_secp521r1.pem process 2  
> bind \*:8097 tfo ssl crt /etc/ssl/certs\_self/ec\_concatenated\_prime256v1.pem crt /etc/ssl/certs\_self/ec\_concatenated\_secp348r1.pem crt /etc/ssl/certs\_self/ec\_concatenated\_secp521r1.pem process 3  
> bind abns@haproxy-clt2 accept-proxy tfo ssl crt /etc/ssl/certs\_self/ec\_concatenated\_prime256v1.pem crt /etc/ssl/certs\_self/ec\_concatenated\_secp348r1.pem crt /etc/ssl/certs\_self/ec\_concatenated\_secp521r1.pem  
> process 4  
> mode tcp  
> option tcplog  
> option tcp-smart-accept  
> default\_backend foscam\_dest\_90
> 
> backend foscam\_dest\_90  
> mode tcp  
> option tcp-smart-connect  
> server ipcam 192.168.0.2:90 check fall 3 rise 2 maxconn 50
