# Multiple port 443 backends - TCP mode

**URL:** <https://discourse.haproxy.org/t/multiple-port-443-backends-tcp-mode/3211>\
**Category:** Help!\
**Created:** [November 9, 2018, 2:49pm UTC](https://discourse.haproxy.org/t/multiple-port-443-backends-tcp-mode/3211 "2018-11-09T14:49:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mysticalunicorn](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@mysticalunicorn](https://discourse.haproxy.org/u/mysticalunicorn)\
**Post date:** [November 9, 2018, 2:49pm UTC](https://discourse.haproxy.org/t/multiple-port-443-backends-tcp-mode/3211/1 "2018-11-09T14:49:59Z")

</div>

currently im listening on port 443 in TCP mode and my attached backend is moving the traffic to an api on port 443 on the server. no issues there.  
I need to have the front end thats listening on port 443 to now have 2 backends and an acl that uses the second backend only when the request is servername/oauth

this second backend will also forward to a server on port 443 ( a different server of course )

I have seen the acl rules for http requests but havent found a good example for port 443.

thanks for any help

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [November 9, 2018, 3:52pm UTC](https://discourse.haproxy.org/t/multiple-port-443-backends-tcp-mode/3211/2 "2018-11-09T15:52:05Z")

</div>

TCP mode without TLS termination I assume? You need to make sure that they don’t have overlapping certificates, then you can content switch based on the SNI value, something like this:

```auto
frontend port443
    bind :443
    tcp-request inspect-delay 5s
    tcp-request content accept if { req_ssl_hello_type 1 }
    use_backend backend1 if { req_ssl_sni -i backend1.example.org }
    use_backend backend2 if { req_ssl_sni -i backend2.example.org }

```

---

<div class="post-metadata">

**Author:** ![mysticalunicorn](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@mysticalunicorn](https://discourse.haproxy.org/u/mysticalunicorn)\
**Post date:** [November 9, 2018, 4:00pm UTC](https://discourse.haproxy.org/t/multiple-port-443-backends-tcp-mode/3211/3 "2018-11-09T16:00:48Z")

</div>

thanks. for our architecture they are using the same cert.  
is there a way to do an acl like so ?

frontend api  
bind \*:443 npn spdy/2 alpn h2,http/1.1  
mode tcp  
acl acl\_oauth path -i /oauth  
use\_backend backend\_oauth if acl\_oauth  
default\_backend api\_backend

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [November 9, 2018, 4:05pm UTC](https://discourse.haproxy.org/t/multiple-port-443-backends-tcp-mode/3211/4 "2018-11-09T16:05:40Z")

</div>

You can do it if the certificate is configured on haproxy, terminating TLS there and using haproxy in http mode. Then you can just use the Host header or something like the path (matching `/oauth`) there.

But you have to decrypt the traffic at haproxy to do this.

> [@mysticalunicorn](#):
>
> `bind *:443 npn spdy/2 alpn h2,http/1.1`

That’s incorrect, you cannot use SSL feature like npn or alpn when your are not terminating SSL.
