# Haproxy - httpd real ip

**URL:** <https://discourse.haproxy.org/t/haproxy-httpd-real-ip/1337>\
**Category:** Help!\
**Created:** [June 17, 2017, 11:20pm UTC](https://discourse.haproxy.org/t/haproxy-httpd-real-ip/1337 "2017-06-17T23:20:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![soume86](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@soume86](https://discourse.haproxy.org/u/soume86)\
**Post date:** [June 17, 2017, 11:20pm UTC](https://discourse.haproxy.org/t/haproxy-httpd-real-ip/1337/1 "2017-06-17T23:20:04Z")

</div>

Hello,

I just installed haproxy as reverse proxy for apache under centos 7.

I configured it to do ssl from end to end (client ← ssl → haproxy ← ssl → srv\_web).

Everything works, the only problem is that at the level of logs apache, it is impossible to have the IP address of the client.

My configuration:

> frontend http-in  
> bind \*:80  
> mode http  
> option httplog  
> redirect scheme https code 301 if !{ ssl\_fc }  
> acl acl1 hdr(host) [domain.fr](http://domain.fr)  
> use\_backend back1 if acl1

> frontend https-in  
> bind \*:443 ssl crt cert.pem no-sslv3  
> mode http  
> option httplog  
> acl acl1 hdr(host) [domain.fr](http://domain.fr)  
> use\_backend back1 if acl1

> backend back1  
> mode http  
> option httpchk  
> option forwardfor except 127.0.0.1  
> http-request add-header X-Forwarded-Proto https if { ssl\_fc }  
> option forwardfor header X-Client  
> server web-server1 10.10.0.1:8443 ssl verify none

In apache : httpd.conf

> LogFormat “%{X-Forwarded-For}i %l %u %t "%r" %\>s %b "%{Referer}i" "%{User-Agent}i"” combined

Would anyone have an idea?

Thank you in advance

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 18, 2017, 8:23pm UTC](https://discourse.haproxy.org/t/haproxy-httpd-real-ip/1337/2 "2017-06-18T20:23:13Z")

</div>

Looks like you configured haproxy to send the client IP in the header X-Client, but Apache expects X-Forwarded-For.

Remove “header X-Client” from the “option forwardfor” directive.

---

<div class="post-metadata">

**Author:** ![soume86](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@soume86](https://discourse.haproxy.org/u/soume86)\
**Post date:** [July 11, 2017, 5:26am UTC](https://discourse.haproxy.org/t/haproxy-httpd-real-ip/1337/3 "2017-07-11T05:26:54Z")

</div>

Thank you for your answer.  
I deleted the line, but nothing changes. It does not always work.

Other ideas?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [July 11, 2017, 6:59am UTC](https://discourse.haproxy.org/t/haproxy-httpd-real-ip/1337/4 "2017-07-11T06:59:30Z")

</div>

Which haproxy release is it?

In 1.4 you need  
option http-server-close

[http://cbonte.github.io/haproxy-dconv/1.5/configuration.html#option%20http-server-close](http://cbonte.github.io/haproxy-dconv/1.5/configuration.html#option%20http-server-close)
