# Reverse Proxy Settings with pfSense

**URL:** <https://discourse.haproxy.org/t/reverse-proxy-settings-with-pfsense/5998>\
**Category:** Help!\
**Created:** [December 7, 2020, 6:47am UTC](https://discourse.haproxy.org/t/reverse-proxy-settings-with-pfsense/5998 "2020-12-07T06:47:58Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![redbor](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@redbor](https://discourse.haproxy.org/u/redbor)\
**Post date:** [December 9, 2020, 11:53pm UTC](https://discourse.haproxy.org/t/reverse-proxy-settings-with-pfsense/5998/3 "2020-12-09T23:53:55Z")

</div>

Thanks for the reply.

We’re using DNS internally to resolve all these names, this is just a placeholder question to make sure that the concept is sound. If you have a moment, would the fact that we’re using DNS to get this done change the ability for HAProxy to do this? I tried playing with “source:” in the _advanced_ back-end options, and briefly messed with X-Forwarded-For headers, but any connection on a protocol other than HTTP was attempted with the _real_ source IP instead of the one I wanted.

I ended up proxying with HAProxy to get past the firewall, and then _proxying again_ with apache to display the content - which successfully allowed me to force both the IP and the protocol for display.

I may have some misunderstanding in the implementation of this (probably do, I’m no expert), but I wasn’t able to find a way to get HAProxy to keep its own IP address for internal connections. I spoke to an expert on corporate-level reverse proxies, and he mentioned that the way it is typically done is to secure the application correctly in the first place so that this kind of proxy is not needed.

For anyone Googling in 2023, hopefully something in here will help.

---

_[View the full topic](https://discourse.haproxy.org/t/reverse-proxy-settings-with-pfsense/5998)._
