# Http to https on same frontend port

**URL:** <https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244>\
**Category:** Help!\
**Created:** [May 18, 2020, 12:40pm UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244 "2020-05-18T12:40:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ivan.efremovski](https://avatars.discourse-cdn.com/v4/letter/i/e8c25b/32.png) [@ivan.efremovski](https://discourse.haproxy.org/u/ivan.efremovski)\
**Post date:** [May 18, 2020, 12:40pm UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244/1 "2020-05-18T12:40:11Z")

</div>

Hi all,

I’m trying to set up HAproxy to send all http request to https follow the same link and port. For example:

[http://exmple.local:9443](http://exmple.local:9443) —\> [https://exmple.local:9443](https://exmple.local:9443)

Here is my configuration:

frontend example  
bind \*:9443 ssl crt /etc/haproxy/example.pem

### Example app

acl is\_example path -i -m beg /example  
use\_backend example\_backend if is\_example

backend example\_backend  
mode http  
balance roundrobin  
server example01 host:9443 check ssl verify none  
server example02 host:9443 check ssl verify none  
http-request set-header X-Forwarded-Port %[dst\_port]  
http-request add-header X-Forwarded-Proto https if { ssl\_fc }

In addiion, i have tried:

redirect scheme https code 301 if !{ ssl\_fc }  
http-request add-header X-Forwarded-Proto https

HAproxy version HA-Proxy version 2.1.4.  
OS: Suse Ent. 15 SP1

Please, suggest configuration.

BR.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [May 18, 2020, 5:53pm UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244/3 "2020-05-18T17:53:41Z")

</div>

This will not work, don’t do it.

---

<div class="post-metadata">

**Author:** ![ivan.efremovski](https://avatars.discourse-cdn.com/v4/letter/i/e8c25b/32.png) [@ivan.efremovski](https://discourse.haproxy.org/u/ivan.efremovski)\
**Post date:** [May 18, 2020, 6:31pm UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244/4 "2020-05-18T18:31:33Z")

</div>

Well, i don’t think i have a choice. Let me explain my situation:

We have IBM Websphere application servers in the backend, listening on 9080 (http) and 9443 (https). I tried to use 443 in frontend and 9080 in backend and when I open the app on **[http://example.com](http://example.com)\exampleapp i get [https://example.com:9080](https://example.com:9080)\exampleapp** and the app is not working. I can’t find what is the problem for this behavior and how to get past it (i think is the application problem, but I’m not sure).

BR.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [May 19, 2020, 6:29am UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244/5 "2020-05-19T06:29:34Z")

</div>

Your assumption that putting everything in one port will solve those issues are wrong.

If the backend redirects, you either try to configure haproxy the same, or configure your backend so it does the proper redirects with correct URLs.

Assuming the host port is not wrong also, to do the former you’d listen on port 9080 and forward to 9080 in HTTP, and 9443 to 9443 for HTTPS.

---

<div class="post-metadata">

**Author:** ![void\_in](https://avatars.discourse-cdn.com/v4/letter/v/3ec8ea/32.png) [@void\_in](https://discourse.haproxy.org/u/void_in)\
**Post date:** [May 27, 2020, 10:27am UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244/6 "2020-05-27T10:27:16Z")

</div>

We faced this same issue a while back where the IBM websphere app servers won’t redirect correctly. The Websphere redirects in a way where the app port is part of the redirect URL. What they suggest and we eventually did is to configure an IHS (IBM HTTPD server) in front of the app servers listening on port 443 and then communicating to backend app servers. The HAProxy will listen on port 443 for https and communicate to IHS backend on 443.

---

<div class="post-metadata">

**Author:** ![ivan.efremovski](https://avatars.discourse-cdn.com/v4/letter/i/e8c25b/32.png) [@ivan.efremovski](https://discourse.haproxy.org/u/ivan.efremovski)\
**Post date:** [May 27, 2020, 7:56pm UTC](https://discourse.haproxy.org/t/http-to-https-on-same-frontend-port/5244/7 "2020-05-27T19:56:57Z")

</div>

Yeah i figured that, but i went without IHS and opened the application server ports (secured) as front-end on HAproxy side. Everything working fine and we are keeping the port in the URL.

Thank you all for posting.
