# SSL Offloading & SSL Passthrough on same port with SNI

**URL:** <https://discourse.haproxy.org/t/ssl-offloading-ssl-passthrough-on-same-port-with-sni/4619>\
**Category:** Help!\
**Created:** [December 12, 2019, 4:14pm UTC](https://discourse.haproxy.org/t/ssl-offloading-ssl-passthrough-on-same-port-with-sni/4619 "2019-12-12T16:14:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![XQR](https://avatars.discourse-cdn.com/v4/letter/x/43a26b/32.png) [@XQR](https://discourse.haproxy.org/u/XQR)\
**Post date:** [December 12, 2019, 4:14pm UTC](https://discourse.haproxy.org/t/ssl-offloading-ssl-passthrough-on-same-port-with-sni/4619/1 "2019-12-12T16:14:00Z")

</div>

Hi everyone,

I’m desperately looking to solve the following problem, but was not able to find the solution on the internet. I was told by someone it should be possible to resolve, but no further hints have been given. That’s where you HAProxy Pros (hopefully) come into play 😉

In case you can help me or point me to the right direction, please also let me know which HAProxy version I need to have in place to make it work.

**CURRENT SITUATION**

- I only have one public IP address
- Got multiple backend servers
- All backend services shall be made publicly available on Port 443
- Based on the backend’s capabilities, I’m forced to SSL offload or passthrough

**DESIRED OUTCOME**

- With the help of SNI, I want to define when an incoming traffic/request is SSL offloaded or SSL passthrough.

**EXAMPLE**

- [A.website.com](http://A.website.com) Port 443 --\> SSL offloading / termination to backend Server A on Port 80
- [B.website.com](http://B.website.com) Port 443 --\> SSL offloading / termination to backend Server B on Port 80
- [C.website.com](http://C.website.com) Port 443 --\> SSL passthrough to backend Server C on Port 443
- [D.website.com](http://D.website.com) Port 443 --\> SSL passthrough to backend Server D on Port 443

If you could provide me a simple HAProxy config with some details, which is able to achieve the outlined desired scenario, I would be greatly thankful.

Thanks in advance for your support,

Sascha

---

<div class="post-metadata">

**Author:** ![simplexion](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/simplexion/32/1858_2.png) [@simplexion](https://discourse.haproxy.org/u/simplexion)\
**Post date:** [December 12, 2019, 10:53pm UTC](https://discourse.haproxy.org/t/ssl-offloading-ssl-passthrough-on-same-port-with-sni/4619/2 "2019-12-12T22:53:26Z")

</div>

Hi Sascha,  
This is exactly what I do. Here is a guide I wrote a while back.

> **[Using Cloudflare with HAProxy](https://simplebeian.wordpress.com/2018/06/18/using-cloudflare-with-haproxy/)**
>
> A while ago I switched to using Cloudflare for my domain names DNS. The main reason I did this was for dynamic DNS since I had a dynamic IP on my home Internet connection. I then looked into what e…

  
The haproxy.cfg should help you out.

A note that if any of the backend servers are using TLS you will need to change the config for the final backend config.  
`server server01 10.0.0.10:80 check`  
would become  
`server server01 10.0.0.10:443 check ssl verify none`

---

<div class="post-metadata">

**Author:** ![Rickard\_505](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@Rickard\_505](https://discourse.haproxy.org/u/Rickard_505)\
**Post date:** [February 12, 2024, 8:45am UTC](https://discourse.haproxy.org/t/ssl-offloading-ssl-passthrough-on-same-port-with-sni/4619/3 "2024-02-12T08:45:31Z")

</div>

The link is not working
