# Can we set one haproxy to deal with multi domains requests ？

**URL:** <https://discourse.haproxy.org/t/can-we-set-one-haproxy-to-deal-with-multi-domains-requests/8516>\
**Category:** Help!\
**Created:** [March 23, 2023, 8:46am UTC](https://discourse.haproxy.org/t/can-we-set-one-haproxy-to-deal-with-multi-domains-requests/8516 "2023-03-23T08:46:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![qq9338745](https://avatars.discourse-cdn.com/v4/letter/q/e8c25b/32.png) [@qq9338745](https://discourse.haproxy.org/u/qq9338745)\
**Post date:** [March 23, 2023, 8:46am UTC](https://discourse.haproxy.org/t/can-we-set-one-haproxy-to-deal-with-multi-domains-requests/8516/1 "2023-03-23T08:46:43Z")

</div>

in the current configuration, we are using [www.abc.com](http://www.abc.com)(suppose is 10.10.10.1) as dns name of haproxy server . it can deal with request of [www.abc.com](http://www.abc.com), just like this  
[www.abc.com/url1](http://www.abc.com/url1) ------\> backend server (host1/host2)   
can we add another domain requests to this haproxy ?  
suppose we want to this haproxy to deal with [www.def.com/url2](http://www.def.com/url2) , can we achieve it with this ?  
1) bind [www.def.com](http://www.def.com) to 10.10.10.1 also.  
2) for https , we will apply one certificates for [www.abc.com](http://www.abc.com) and [www.def.com](http://www.def.com)  
3) create a policy , forward the url begin with url2 to the backend server host3/host4 ?

---

<div class="post-metadata">

**Author:** ![stormrover](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/stormrover/32/1847_2.png) [@stormrover](https://discourse.haproxy.org/u/stormrover)\
**Post date:** [March 23, 2023, 1:16pm UTC](https://discourse.haproxy.org/t/can-we-set-one-haproxy-to-deal-with-multi-domains-requests/8516/2 "2023-03-23T13:16:40Z")

</div>

Should look something like this:

```auto
# You can put multiple certs on your bind line like this.
bind 10.10.10.1:443 ssl /path/to/abc.com.pem crt /path/to/def.com.pem
	# "is_abc" or "is_def" becomes true of the request host header matches.
	acl is_abc hdr(host) -i www.abc.com
	acl is_def hdr(host) -i www.def.com
	# If a host matches, route to that backend.
	use_backend abc if is_abc
	use_backend def if is_def
	# If no host matches, use this backend.
	default_backend no_route

backend abc
	server host1 ...
	server host2...

backend def
	server host3...
	server host4...

backend no_route
	http-request deny deny_status 403

```

Edit: There should not be a space in the bind line between the IP and port: `10.10.10.1:443`

---

<div class="post-metadata">

**Author:** ![CharlesJamesFox](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/charlesjamesfox/32/1258_2.png) [@CharlesJamesFox](https://discourse.haproxy.org/u/CharlesJamesFox)\
**Post date:** [June 20, 2023, 6:12pm UTC](https://discourse.haproxy.org/t/can-we-set-one-haproxy-to-deal-with-multi-domains-requests/8516/3 "2023-06-20T18:12:00Z")

</div>

> [@stormrover](#):
>
> ```auto
> # You can put multiple certs on your bind line like this.
> bind 10.10.10.1:443 ssl /path/to/abc.com.pem crt /path/to/def.com.pem
> 
> ```

You can also specify a folder on the `bind` line and place all your concatenated `.pem` files into it. For example:

```auto
    bind *:443 ssl crt /etc/haproxy/certificates/ alpn h2,http/1.1

```

If you do this, the client will pick the correct certificate based on SNI (Server Name Indication). Make sure that you don’t leave multiple certificates for the same domain in that folder. If you do, the client could potentially pick the wrong one, and then you’ll get errors if the one it chooses is expired or misconfigured in some way.
