# Force http/1.1 on backend connection

**URL:** <https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050>\
**Category:** Help!\
**Created:** [October 9, 2025, 12:29pm UTC](https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050 "2025-10-09T12:29:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Larsen](https://avatars.discourse-cdn.com/v4/letter/l/90ced4/32.png) [@Larsen](https://discourse.haproxy.org/u/Larsen)\
**Post date:** [October 9, 2025, 12:29pm UTC](https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050/1 "2025-10-09T12:29:13Z")

</div>

Hi,

we recently upgraded our HAProxy server from Debian Bookworm to Trixie, thereby updating HAProxy from 2.6.12 to 3.0.11. Since then, a Linux client using Evolution cannot connect to the Exchange server anymore as he repeatedly gets asked for his credentials.

This seems to be caused by ALPN making http/2 available for the frontend by default, which Exchange as the backend is not compatible with as far as I could find.

I want to force HAProxy to use http/1.1 for connections with this backend (not the others) while the frontend should still offer all versions. However, logging shows that this setting seems to be ignored.

/etc/haproxy/haproxy.cfg:

> backend ExchangeEWS  
> option httpchk GET /ews  
> http-check expect status 401  
> server atl-ex2019 192.168.120.3:443 ssl verify none alpn http/1.1

Logging is done with:

> frontend fe  
> log-format “%ci:%cp [%tr] %ft %b/%s %ST %B {req\_proto=%HV} → {res\_proto=%HV}”

Log shows:

> Oct 09 13:07:26 atl-proxy haproxy[75200]: 192.168.120.38:34924 [09/Oct/2025:13:07:26.024] fe~ ExchangeEWS/atl-ex2019 401 660 {req\_proto=HTTP/2.0} → {res\_proto=HTTP/2.0}

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 9, 2025, 1:06pm UTC](https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050/2 "2025-10-09T13:06:03Z")

</div>

Backend traffic is http/1.1 by default. Your configuration does absolutely nothing, other than enabling ALPN and negotiating http/1.1 towards your backend server. You don’t need to disable H2 on the backend because it was never on in the first place.

H2 on the frontend is a different thing. When you put `alpn http/1.1` on your bind line in the frontend, the problem is gone?

> [@Larsen](#):
>
> However, logging shows that this setting seems to be ignored.

`%HV` shows the _request_ HTTP version between the client and haproxy. It has nothing to do with the backend HTTP version.

You are showing the same variable twice, I don’t know why you expect a different result.

---

<div class="post-metadata">

**Author:** ![Larsen](https://avatars.discourse-cdn.com/v4/letter/l/90ced4/32.png) [@Larsen](https://discourse.haproxy.org/u/Larsen)\
**Post date:** [October 9, 2025, 3:08pm UTC](https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050/3 "2025-10-09T15:08:14Z")

</div>

> [@lukastribus](#):
>
> You are showing the same variable twice, I don’t know why you expect a different result.

Should have checked the output of ChatGPT more thoroughly… looked fine to me and I didn’t notice this blunder 🤦‍♂️

Changing the bind line fixes the problem.

Not sure though why exactly: When Exchange (according to ChatGPT) has problems with h2, but HAProxy already uses h1.1 communicating with Exchange, why does changing the frontend make a difference?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 9, 2025, 3:43pm UTC](https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050/4 "2025-10-09T15:43:14Z")

</div>

It’s not that the exchange server has a bug that when exposed to H2 it fails.

It’s that [windows authentication (NTLM/Kerberos/Negotiate) is not supported with HTTP/2](https://learn.microsoft.com/en-us/iis/get-started/whats-new-in-iis-10/http2-on-iis#when-is-http2-not-supported) at all.

Therefor “hiding” H2 from Exchange does not solve the problem, because you need http/1.1 end-to-end.

If you have terminate multiple services on a single IP and port, you can configure ALPN selectively with crt-list (based on hostnames):

> **[HAProxy version 3.0.12-1 - Configuration Manual](https://docs.haproxy.org/3.0/configuration.html#5.1-crt-list)**

I would recommend not using overlapping certifcates though.

---

<div class="post-metadata">

**Author:** ![Larsen](https://avatars.discourse-cdn.com/v4/letter/l/90ced4/32.png) [@Larsen](https://discourse.haproxy.org/u/Larsen)\
**Post date:** [October 10, 2025, 8:38am UTC](https://discourse.haproxy.org/t/force-http-1-1-on-backend-connection/12050/5 "2025-10-10T08:38:53Z")

</div>

Thanks for the clarification!
