# Use haproxy with http2 backends and non http2 backends

**URL:** <https://discourse.haproxy.org/t/use-haproxy-with-http2-backends-and-non-http2-backends/1637>\
**Category:** Help!\
**Created:** [October 5, 2017, 6:15am UTC](https://discourse.haproxy.org/t/use-haproxy-with-http2-backends-and-non-http2-backends/1637 "2017-10-05T06:15:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bend66](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/bend66/32/74_2.png) [@bend66](https://discourse.haproxy.org/u/bend66)\
**Post date:** [October 5, 2017, 6:15am UTC](https://discourse.haproxy.org/t/use-haproxy-with-http2-backends-and-non-http2-backends/1637/1 "2017-10-05T06:15:24Z")

</div>

Hi,

I have an haproxy configuration where one frontend redirects to multiple backend depending on the SNI.

However I want to switch one of those backends to http2 and keep all the other on http1.1

My problem is I can’t find a way to tell haproxy that it should only accept http1 for a backend and accept http1 and http2 for the other.

Any idea if it feasible or not ?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 5, 2017, 7:35am UTC](https://discourse.haproxy.org/t/use-haproxy-with-http2-backends-and-non-http2-backends/1637/2 "2017-10-05T07:35:20Z")

</div>

Yes, set it up like this:

> [@How to set ssl verify client for specific domain name](https://discourse.haproxy.org/t/how-to-set-ssl-verify-client-for-specific-domain-name/1489/3):
>
> There is no simple way to do this, unfortunately. Use a TCP frontend withouth SSL termination, SNI route to different backends that recirculate to traffic to dedicated SSL frontends with different configurations. Something like: frontend port443 bind :443 tcp-request inspect-delay 5s tcp-request content accept if { req\_ssl\_hello\_type 1 } use\_backend recir\_clientcertenabled if { req\_ssl\_sni -i test1.demo.com } default\_backend recir\_default backend recir\_clientcertenabled …

Make sure you have dedicated certificates for HTTP/2 and HTTP/1, without overlapping SANs, otherwise SNI routing fails.

Also, yuor backend has to support HTTP/2 for this, as Haproxy doesn’t (so we need to tunnel).
