# SSL Termination for MSSQL

**URL:** <https://discourse.haproxy.org/t/ssl-termination-for-mssql/4611>\
**Category:** Help!\
**Created:** [December 10, 2019, 11:36am UTC](https://discourse.haproxy.org/t/ssl-termination-for-mssql/4611 "2019-12-10T11:36:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mr.Error](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@Mr.Error](https://discourse.haproxy.org/u/Mr.Error)\
**Post date:** [December 10, 2019, 11:36am UTC](https://discourse.haproxy.org/t/ssl-termination-for-mssql/4611/1 "2019-12-10T11:36:21Z")

</div>

Hi everyone,

what i am Trying to archive is to use haproxy 2.0.10 as SSL Proxy for an MS-SQL Server. The Connection to the backend has to be established without SSL.

I am usind the following (simple) config:

listen 30-MSSQL\_tcp  
bind 10.40.0.11:1433 ssl crt /etc/pki/bundle/wildcard.domain.tld.bundle.pem  
mode tcp  
option tcplog  
option tcpka  
server 11.22.33.44:1433 inter 1s rise 1 fall 1

It works when i disable SSL. Has anyone ever archived a Setup like that. Or is it just impossible?

Any help or Input is highly appreciated!

---

<div class="post-metadata">

**Author:** ![harporb](https://avatars.discourse-cdn.com/v4/letter/h/7993a0/32.png) [@harporb](https://discourse.haproxy.org/u/harporb)\
**Post date:** [December 20, 2019, 8:43pm UTC](https://discourse.haproxy.org/t/ssl-termination-for-mssql/4611/2 "2019-12-20T20:43:14Z")

</div>

I have yet to become familiar with the all in on listen vip. I dont see any glaring config issues. Have you tried splitting it up into a frontend and backend section? Im not sure if it performs any different but suggesting an alternative.

Is the back end healthy? I know when i dont have a check it will not not the servers are up in my stats page. I added the check below…

> frontend [server123.something.com](http://server123.something.com)  
> mode tcp  
> option tcplog  
> option tcpka  
> bind 10.40.0.11:1433 ssl crt /etc/pki/bundle/wildcard.domain.tld.bundle.pem  
> default\_backend server123
> 
> backend server123  
> mode tcp  
> balance roundrobin  
> server 11.22.33.44:1433 check inter 1s rise 1 fall 1

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 21, 2019, 10:35am UTC](https://discourse.haproxy.org/t/ssl-termination-for-mssql/4611/3 "2019-12-21T10:35:34Z")

</div>

If it works for you when you disable SSL in the frontend section of haproxy, that simply means you did not enable SSL on your client.
