# Help me with ACL for TCP

**URL:** <https://discourse.haproxy.org/t/help-me-with-acl-for-tcp/5524>\
**Category:** Help!\
**Created:** [July 24, 2020, 11:47am UTC](https://discourse.haproxy.org/t/help-me-with-acl-for-tcp/5524 "2020-07-24T11:47:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![oken](https://avatars.discourse-cdn.com/v4/letter/o/b9bd4f/32.png) [@oken](https://discourse.haproxy.org/u/oken)\
**Post date:** [July 24, 2020, 11:47am UTC](https://discourse.haproxy.org/t/help-me-with-acl-for-tcp/5524/1 "2020-07-24T11:47:23Z")

</div>

I want to use HAProxy to redirect services based on domain name.

i.e.  
[host1.example.com](http://host1.example.com) --\> service1  
[host2.example.com](http://host2.example.com) --\> service2

How should I proceed?

---

<div class="post-metadata">

**Author:** ![maxtim](https://avatars.discourse-cdn.com/v4/letter/m/838e76/32.png) [@maxtim](https://discourse.haproxy.org/u/maxtim)\
**Post date:** [July 25, 2020, 3:40am UTC](https://discourse.haproxy.org/t/help-me-with-acl-for-tcp/5524/2 "2020-07-25T03:40:37Z")

</div>

It’s been my n00b experience that there are some questions that you must first answer before proceeding.

Mainly these questions have to do with certificates. (I hope I don’t confuse more)

What service will handle the certs? In my case, I used certbot to generate certs for [example1.com](http://example1.com) and [example2.com](http://example2.com). In my case, I did not want haproxy to do anything with certs.

See: [https://www.haproxy.com/documentation/haproxy/deployment-guides/tls-infrastructure/](https://www.haproxy.com/documentation/haproxy/deployment-guides/tls-infrastructure/)

if you want haproxy to handle certs; See: [https://www.haproxy.com/blog/haproxy-ssl-termination/](https://www.haproxy.com/blog/haproxy-ssl-termination/)

That is, unfortunately, the limits of my knowledge.
