# HAProxy forwarding HTTPS OK, TCP not OK. Please help!

**URL:** <https://discourse.haproxy.org/t/haproxy-forwarding-https-ok-tcp-not-ok-please-help/3872>\
**Category:** Help!\
**Created:** [May 29, 2019, 8:28am UTC](https://discourse.haproxy.org/t/haproxy-forwarding-https-ok-tcp-not-ok-please-help/3872 "2019-05-29T08:28:59Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 4, 2019, 10:45am UTC](https://discourse.haproxy.org/t/haproxy-forwarding-https-ok-tcp-not-ok-please-help/3872/10 "2019-06-04T10:45:00Z")

</div>

> [@Brizoo](#):
>
> But nothing is working anymore after this change. How can I check the logs to see if the public IP is correctly coming to HaProxy server?

The question is only, are the ip addresses X.Y.Z.A and X.Y.Z.B properly configured on this box and reachable from your network?

If you bind to something that doesn’t work anyway, it won’t work of course.

> [@Brizoo](#):
>
> Another thing, now since I have mutliple frontends, I might be able to use HTTP mode for some of them when appropriate, and after an SSL termination on HAProxy, I could use the hdr(dom) value to identify and forward to the good backends.  
> What do you think?

I’m not sure all of those services are actually HTTP, and also, you would need to have all the certificates with private keys configured with haproxy. This becomes way more complicated than the current configuration.

Whether that’s a good idea depends on what those services are, but it sounds to me like they are more complicated than simple HTTP(S) sites.

> [@Brizoo](#):
>
> Another thing, despite the fact FortiEMS backend is alone using ports 8013 and 8014, I have a timeout when I telnet [fortiems.domain.com](http://fortiems.domain.com) 8013. And my clients are still not connecting to that service.  
> This is not related to another service using the same port or anything, It looks like HaProxy is just never forwarding the connections.

Enable [logging](https://discourse.haproxy.org/t/how-to-enable-haproxy-stats-log/1738/2) (but use `option tcplog` instead of http mode) and check out the logs.

---

_[View the full topic](https://discourse.haproxy.org/t/haproxy-forwarding-https-ok-tcp-not-ok-please-help/3872)._
