# SSL/TLS offloading / Let's Encrypt - tcp only

**URL:** <https://discourse.haproxy.org/t/ssl-tls-offloading-lets-encrypt-tcp-only/3612>\
**Category:** Help!\
**Created:** [March 12, 2019, 9:46pm UTC](https://discourse.haproxy.org/t/ssl-tls-offloading-lets-encrypt-tcp-only/3612 "2019-03-12T21:46:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rodman](https://avatars.discourse-cdn.com/v4/letter/r/edb3f5/32.png) [@Rodman](https://discourse.haproxy.org/u/Rodman)\
**Post date:** [March 12, 2019, 9:46pm UTC](https://discourse.haproxy.org/t/ssl-tls-offloading-lets-encrypt-tcp-only/3612/1 "2019-03-12T21:46:06Z")

</div>

Hello team

I have task to reroute socket connection via SSL/TLS port to noSSL port with

I have task to:

1. receive TCP incoming socket connection with SSL/TLS verification (with Let’s Encrypt certificate for domain) - port 3433
2. Decrypt data and resend (no SSL/TLS) data to port 3000 on same server
3. sure keep such socket connection a long time alive

I found such description - [https://www.haproxy.com/documentation/haproxy/deployment-guides/tls-infrastructure/#ssl-tls-offloading](https://www.haproxy.com/documentation/haproxy/deployment-guides/tls-infrastructure/#ssl-tls-offloading)

But cant understand:

1. this config i have to replace default config?
2. how can i connect Let’s Encrypt certificate?
3. Enable full logs

Help me please on this config.  
How real config have to be?

Thanks

---

<div class="post-metadata">

**Author:** ![gerald](https://avatars.discourse-cdn.com/v4/letter/g/ea666f/32.png) [@gerald](https://discourse.haproxy.org/u/gerald)\
**Post date:** [March 18, 2019, 4:28am UTC](https://discourse.haproxy.org/t/ssl-tls-offloading-lets-encrypt-tcp-only/3612/2 "2019-03-18T04:28:52Z")

</div>

Hi, I had the same issue.  
It is commonly referred to as SSL termination, here are a few links with some example configs

> **[HAProxy with SSL termination](https://medium.com/@michaelmaier_32241/haproxy-with-ssl-termination-6002f274a506)**
>
> Problem

What is critical is to ensure you place the following in the “backend” configuration

http-request set-header X-Forwarded-Port %[dst\_port]  
http-request add-header X-Forwarded-Proto https if { ssl\_fc }

and make sure you check for cookies or you will have problems with sessions.

The following is the “stock” config used for development servers

backend dev4-backend  
mode http  
log global  
timeout connect 30000  
timeout server 30000  
retries 3  
option forwardfor  
cookie SERVERID insert indirect nocache  
option http-server-close  
http-request set-header X-Forwarded-Port %[dst\_port]  
http-request set-header X-Forwarded-Proto https if { ssl\_fc }  
server dev4 192.168.10.54:80 check inter 1000 check cookie dev4

hope this helps,

Cheers,  
Gerald

---

<div class="post-metadata">

**Author:** ![void\_in](https://avatars.discourse-cdn.com/v4/letter/v/3ec8ea/32.png) [@void\_in](https://discourse.haproxy.org/u/void_in)\
**Post date:** [March 20, 2019, 6:21am UTC](https://discourse.haproxy.org/t/ssl-tls-offloading-lets-encrypt-tcp-only/3612/3 "2019-03-20T06:21:13Z")

</div>

frontend my\_front\_end\_serv  
bind 0.0.0.0:3433  
mode http  
option httplog  
default\_backend my\_backend\_serv

backend my\_backend\_serv  
mode http  
default-server inter 10s fall 3 rise 2  
balance roundrobin  
cookie SERVERID insert indirect nocache  
http-request set-header X-Forwarded-Port %[dst\_port]  
http-request set-header X-Forwarded-Proto https if {ssl\_fc}  
option forwardfor  
server SERVER1 127.0.0.1:3000 check inter 5s cookie SERVER1

Cookie check is not required in case it is one server and you don’t need session sticky-ness. However, if authentication cookies are involved, then you need to have sticky sessions.

Keep alive is the default behavior of HAProxy since version 1.5 so that shouldn’t be a problem.
