# HAProxy OpenLDAP transparent

**URL:** <https://discourse.haproxy.org/t/haproxy-openldap-transparent/1871>\
**Category:** Help!\
**Created:** [December 5, 2017, 3:29pm UTC](https://discourse.haproxy.org/t/haproxy-openldap-transparent/1871 "2017-12-05T15:29:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hakim42](https://avatars.discourse-cdn.com/v4/letter/h/58956e/32.png) [@hakim42](https://discourse.haproxy.org/u/hakim42)\
**Post date:** [December 5, 2017, 3:29pm UTC](https://discourse.haproxy.org/t/haproxy-openldap-transparent/1871/1 "2017-12-05T15:29:26Z")

</div>

Hy,  
I use HAProxy for LDAP with two nodes.  
My problem is that connection logs in LDAP server show IP address from HAProxy but not of clients.

I saw that it is possible two forward address in HTTP mode but i didn’t find for TCP mode.  
My configuration is :

defaults  
log global  
option tcplog  
option dontlognull

# LDAP

frontend ldap\_service\_front  
mode tcp  
bind \*:389  
description LDAP Service  
option socket-stats  
option tcpka  
timeout client 300s  
default\_backend ldap\_service\_back

backend ldap\_service\_back  
option ldap-check  
server [ldap-ha1.domain.com](http://ldap-ha1.domain.com) 192.168.0.10:3899 check addr 192.168.0.10  
server [ldap-ha2.domain.com](http://ldap-ha2.domain.com) 192.168.0.11:3899 check addr 192.168.0.11  
mode tcp  
balance leastconn  
timeout server 300s  
timeout connect 1s

Have you any idea for connection being transparent sending clients IP address to LDAP Server ?

Best Regards

---

<div class="post-metadata">

**Author:** ![AaronWest](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/aaronwest/32/164_2.png) [@AaronWest](https://discourse.haproxy.org/u/AaronWest)\
**Post date:** [December 7, 2017, 11:53am UTC](https://discourse.haproxy.org/t/haproxy-openldap-transparent/1871/2 "2017-12-07T11:53:17Z")

</div>

What you need(And maybe don’t want) is Tproxy…

> **[Configure HAProxy with TPROXY kernel for full transparent proxy](https://www.loadbalancer.org/blog/configure-haproxy-with-tproxy-kernel-for-full-transparent-proxy/)**
>
> If you use HaProxy as the load balancer then all of the backend servers see the traffic coming from the IP address of the load balancer. TPROXY allows you to make sure the backend servers see the true client IP address in the logs. NB. Standard...

You’ll probably need to switch to a two arm config(or solve the routing issue for local clients) but this will make HAproxy fully source IP transparent.

---

<div class="post-metadata">

**Author:** ![Valanthe](https://avatars.discourse-cdn.com/v4/letter/v/c6cbf5/32.png) [@Valanthe](https://discourse.haproxy.org/u/Valanthe)\
**Post date:** [January 22, 2018, 1:30pm UTC](https://discourse.haproxy.org/t/haproxy-openldap-transparent/1871/3 "2018-01-22T13:30:09Z")

</div>

You can try “send\_proxy” option which is tcp equivalent of HTTP “forwarded for” header. Check if openldap is able to handle it.

backend ldap\_service\_back  
option ldap-check  
server [ldap-ha1.domain.com](http://ldap-ha1.domain.com) 192.168.0.10:3899 check addr 192.168.0.10 **send\_proxy**  
server [ldap-ha2.domain.com](http://ldap-ha2.domain.com) 192.168.0.11:3899 check addr 192.168.0.11 **send\_proxy**  
mode tcp  
balance leastconn  
timeout server 300s  
timeout connect 1s

---

<div class="post-metadata">

**Author:** ![hakim42](https://avatars.discourse-cdn.com/v4/letter/h/58956e/32.png) [@hakim42](https://discourse.haproxy.org/u/hakim42)\
**Post date:** [January 23, 2018, 9:48am UTC](https://discourse.haproxy.org/t/haproxy-openldap-transparent/1871/4 "2018-01-23T09:48:59Z")

</div>

Thanks for answering.  
I already tried it but it seems not to work for OpenLDAP.  
I don’t see source IP in OpenLDAP logs.
