# Transparent HAProxy and Exchange not working

**URL:** <https://discourse.haproxy.org/t/transparent-haproxy-and-exchange-not-working/1036>\
**Category:** Help!\
**Created:** [February 27, 2017, 8:51pm UTC](https://discourse.haproxy.org/t/transparent-haproxy-and-exchange-not-working/1036 "2017-02-27T20:51:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dskriv](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@dskriv](https://discourse.haproxy.org/u/dskriv)\
**Post date:** [February 27, 2017, 8:51pm UTC](https://discourse.haproxy.org/t/transparent-haproxy-and-exchange-not-working/1036/1 "2017-02-27T20:51:11Z")

</div>

Hello,

I am attempting to setup a pair of HAProxy servers running CentOS 7 to load balance 2 Exchange 2016 servers transparently. We have logging requirements so the client IP address must be logged on the Exchange side. I have non-transparent setup functioning with layer 7. I followed the instructions here: [http://blog.haproxy.com/2013/09/16/howto-transparent-proxying-and-binding-with-haproxy-and-aloha-load-balancer/](http://blog.haproxy.com/2013/09/16/howto-transparent-proxying-and-binding-with-haproxy-and-aloha-load-balancer/) however when I have ‘source 0.0.0.0 usesrc clientip’ defined in the backends my pages do not load I also do not see errors logged in /var/log/haproxy.log.

I have verified the tproxy module is loaded:  
lsmod | grep -ie tproxy  
xt\_TPROXY 17327 0  
nf\_defrag\_ipv6 35104 3 xt\_socket,xt\_TPROXY,nf\_conntrack\_ipv6  
nf\_defrag\_ipv4 12729 3 xt\_socket,xt\_TPROXY,nf\_conntrack\_ipv4

I replaced firewalld with iptables to allow me to follow the documentation.

All servers are in the same subnet: 192.168.5.0/24  
keepalived VIP 192.168.5.205  
HAProxy-01: 192.168.5.206  
HAProxy-01: 192.168.5.207  
Ex2016-01: 192.168.5.181  
Ex2016-01: 192.168.5.182

I am testing from a different subnet: 192.168.6.0/24

I feel like I am missing something but do not know what.

Here is my config:  
global  
log 127.0.0.1 local0 info  
maxconn 10000  
chroot /var/lib/haproxy  
daemon  
quiet  
tune.ssl.default-dh-param 2048

defaults  
log global  
mode http  
option httplog  
option dontlognull  
timeout connect 30000ms  
timeout client 30000ms  
timeout server 60000ms  
timeout check 60000ms

listen stats  
bind 192.168.5.206:8181  
mode http  
log global  
maxconn 10  
clitimeout 100s  
srvtimeout 100s  
contimeout 100s  
timeout queue 100s  
stats enable  
stats hide-version  
stats refresh 30s  
stats show-node  
stats auth admin:  
stats uri /haproxy?stats

frontend fe\_ex2016  
mode http  
bind 192.168.5.205:80 transparent  
bind 192.168.5.205:443 transparent ssl crt /etc/ssl/certs/ssl\_cert.pem  
redirect scheme https code 301 if !{ ssl\_fc }  
acl autodiscover url\_beg /Autodiscover  
acl mapi url\_beg /mapi  
acl rpc url\_beg /rpc  
acl owa url\_beg /owa  
acl eas url\_beg /microsoft-server-activesync  
acl ecp url\_beg /ecp  
acl ews url\_beg /ews  
acl oab url\_beg /oab  
use\_backend be\_ex2016\_autodiscover if autodiscover  
use\_backend be\_ex2016\_mapi if mapi  
use\_backend be\_ex2016\_rpc if rpc  
use\_backend be\_ex2016\_owa if owa  
use\_backend be\_ex2016\_eas if eas  
use\_backend be\_ex2016\_ecp if ecp  
use\_backend be\_ex2016\_ews if ews  
use\_backend be\_ex2016\_oab if oab  
default\_backend be\_ex2016

backend be\_ex2016\_autodiscover  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /autodiscover/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_mapi  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /mapi/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_rpc  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /rpc/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_owa  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /owa/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_eas  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /microsoft-server-activesync/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_ecp  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /ecp/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_ews  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /ews/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016\_oab  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
option httpchk GET /oab/healthcheck.htm  
option log-health-checks  
http-check expect status 200  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

backend be\_ex2016  
mode http  
source 0.0.0.0 usesrc clientip  
balance roundrobin  
server vm-ex2016-01 192.168.5.181:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt  
server vm-ex2016-02 192.168.5.182:443 check ssl inter 15s verify required ca-file /etc/ssl/certs/ca-bundle.crt

listen smtp  
bind 192.168.5.206:25 transparent  
mode tcp  
source 0.0.0.0 usesrc clientip  
option tcplog  
balance roundrobin  
option smtpchk EHLO [mail.mydomain.net](http://mail.mydomain.net)  
server vm-ex2016-01 192.168.5.181:25 check  
server vm-ex2016-02 192.168.5.182:25 check

---

<div class="post-metadata">

**Author:** ![AaronWest](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/aaronwest/32/164_2.png) [@AaronWest](https://discourse.haproxy.org/u/AaronWest)\
**Post date:** [March 20, 2017, 2:18am UTC](https://discourse.haproxy.org/t/transparent-haproxy-and-exchange-not-working/1036/2 "2017-03-20T02:18:29Z")

</div>

When using TPROXY you need to have all reply traffic go back via HAproxy, this is most usually accomplished by setting the real servers to use the HAProxy host as it’s default gateway. Because of this it often also requires a 2 arm(subnet) setup unless all clients are from an external subnet as yours are.
