(Updated Video In Description) How To Setup ACME, Let's Encrypt, and HAProxy HTTPS on pfsense

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024
  • Updated Version of this video here:
    • How To Guide For HAPro...
    lawrence.video...
    How To Guide For HAProxy and Let's Encrypt on pfSense: Detailed Steps for Setting Up Reverse Proxy
    • How To Guide For HAPro...
    Amazon Affiliate Store
    ➡️ www.amazon.com...
    Gear we used on Kit (affiliate Links)
    ➡️ kit.co/lawrenc...
    Try ITProTV free of charge and get 30% off!
    ➡️ go.itpro.tv/lts
    Use OfferCode LTSERVICES to get 5% off your order at
    ➡️ lawrence.video...
    Tesla Referral Program Offer
    🚘 www.tesla.com/...
    Lawrence Systems Shirts and Swag
    👕 teespring.com/...
    Digital Ocean Offer Code
    ➡️ m.do.co/c/85de...
    HostiFi UniFi Cloud Hosting Service
    ➡️ hostifi.net/?v...
    Protect you privacy with a VPN from Private Internet Access
    ➡️ www.privateint...
    Google Fi Service Referral Code
    📱g.co/fi/r/TA02XR
    More Of Our Affiliates that help us out and can get you discounts!
    ➡️ www.lawrencesy...
    Twitter
    🐦 / tomlawrencetech
    Patreon
    🔗 / lawrencesystems
    Our Forums
    🔗 forums.lawrenc...
    GitHub
    🔗 github.com/law...
    Discord
    🔗 / discord
    Our Web Site
    🔗 www.lawrencesy...
    www.haproxy.co...
    Netgate Hangout Videos
    Let's Encrypt on pfSense
    • Let's Encrypt on pfSense
    Server Load Balancing on pfSense 2.4
    • Server Load Balancing ...
    #pfsense #Firewalls

Комментарии • 188

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS  6 месяцев назад +1

    Updated Video here
    ruclips.net/video/bU85dgHSb2E/видео.html

  • @jrtapley
    @jrtapley 4 года назад +15

    I’ve spent so many hours getting this running. This is a long overdue video. Thanks for making it!

  • @WapitiEater
    @WapitiEater 2 года назад +1

    Good help, thanks. PLT: Disable any existing NAT rules that may exist from previous efforts. Lost about half a day for I 'twigged on to that one. Once NAT was out of the way, this worked perfectly. Thanks!

  • @CookieStealer559
    @CookieStealer559 Год назад

    3 years later and this is still great! Thanks a lot!

  • @S3ANZ13
    @S3ANZ13 2 года назад +10

    You know the one bad thing about tutorials that start with things already set up? .... Me not checking the HAProxy "Settings" panel to see if it's even enabled.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад +1

      It's always those little details.

    • @h1lari0
      @h1lari0 Год назад

      Increasing the maximum connections help as well. 😊

  • @bdorr17
    @bdorr17 4 года назад +3

    Aside from pointing out the one config issue (maybe), Thanks for the video, this was absolutely useful and awesome and I love to not have to port forward and open up 80 just to let letsencrypt verify my cert. This is much more secure method and I really appreciate it

  • @heavy1metal
    @heavy1metal 4 года назад +8

    Instead of only using a default backend, you'd just create the ACL > action. Prevents people from just hitting your IP:PORT and successfully getting the service without the FQDN. Generally I would avoid a default backend going to a valid service. An example of a use case, is I'm currently using the default to redirect to a backend that redirects to a TCP frontend for non web-services. TCP front has its own ACL to match against, but you get the idea.

    • @BorisJohnsonMayor
      @BorisJohnsonMayor Год назад

      What about the default certificate for the frontend. It requires one, so is it a problem?

  • @kevinmiddleton6930
    @kevinmiddleton6930 2 года назад

    This video provided that "ah-ha" moment that I needed for my wildcard cert to work in haproxy. Now I can move away from my other load balancer / reverse proxy tool that I have been using and centralize on pfSense.
    Thank you!

  • @raymondfb
    @raymondfb Год назад

    great video, head still spinning a little. slick as snot when it gets up and runs. thank you again for taking the time to make your videos. learned so much.

  • @CAHOP2401
    @CAHOP2401 4 года назад +4

    This is perfect. Been looking for a video like this

  • @taylom1980
    @taylom1980 3 года назад

    This video is AWESOME! It totally helped me out with redirecting multiple subdomains to different ports on a single server. Thank you so much for showing me how to do this!

  • @MannyCastilloPage
    @MannyCastilloPage 4 года назад +1

    Didn't see your usual outro where you "and thank you for making it to the end of the video" :) thanks for this video

  • @daniellunateel
    @daniellunateel 3 года назад +3

    This video was super helpful but I really wish you had covered the firewall rules in some more depth.
    I was having a ton of trouble until I thought to change the firewall rule to allow access to LAN Net instead of to the firewall itself.
    Maybe this is super obvious to everyone else but I completely missed it for hours.

  • @Herkullainen
    @Herkullainen 4 года назад +1

    This, Jen, is the Internet.

  • @AaronStuder
    @AaronStuder 4 года назад +5

    33:05 Don't you need to copy the "restart" at the end as well?

  • @memphis2k
    @memphis2k 3 года назад +1

    Great video. I was under the impression that this didn't expose port 443 to the internet. But it does. Still more secure than exposing an server I'm suspecting.

  • @vicoscugnizzo3154
    @vicoscugnizzo3154 8 месяцев назад

    Many thanks for many years of contributing to shape a generation of professionals and enthusiasts like me. Pls. do you mind if I make a humble request? IPv6 setups, same videos you made before but emphasizing IPv6 in many forms SLAAC, DHCPv6. Reckon you will be supporting this transition and untangle this complicated setup. I believe many people is avoiding afraid not be able to deliver with quality as the y do in IPv4. Much appreciated.

  • @fonte935
    @fonte935 4 года назад +1

    Such a cool video, Tom. It's taken me more than a few views to digest it all, and now I am trying it on my server. We'll see how it goes! :)

  • @deafno
    @deafno 2 года назад +2

    16:30 The certs in Backend / Server list are not required to get frontend HTTPS offloading to work. I beleive this is for validating backend SSL certs instead.

  • @zoey101dogwablog
    @zoey101dogwablog Год назад

    love the hl2 reference with nova prospekt

  • @theshuz
    @theshuz 4 года назад

    I've used this on pfSense for years!!! Works great!!!👍

  • @michaelmauer1385
    @michaelmauer1385 2 года назад

    Thx, the additional certificates (frontend) was key in my search! Thank you

  • @EduardoReyesDPM
    @EduardoReyesDPM 4 года назад +1

    Literally working on this last night using cloudflare with dns mode.... Ty

  • @Dorff_Meister
    @Dorff_Meister 2 года назад

    Thanks! I've been wanting to do this for a long time and now it's all working on my Netgate/pfSense. My biggest mistake in the process was not moving pfSense from 443 before enabling things. Doh.

  • @Sladeofdark
    @Sladeofdark 4 года назад +3

    fuuuuuuuuuuuu...ck. will i ever understand certificates? why am i so facinated with this mess lol. Awesome content sir!

    • @chris11d7
      @chris11d7 3 года назад +1

      it's like in middle school when you create a secret language with your friends. you and your friends know how to interpret what you're saying because they have the legend, and in order for anyone else to understand, they also need the legend.
      You distribute the legend to only people who are allowed to know what you are saying.
      The CA (certificate authority) verifies my identity to make sure I'm not pretending to be someone else.

  • @NT-zg2hj
    @NT-zg2hj 4 года назад +3

    Hi Lawerance, Hope your well. Thanks for the video. I have a NAS box which I would like to keep local. Would you mind doing another similar video but only for a local network (Private) Thanks

  • @alphabanks
    @alphabanks 4 года назад +2

    This was an amazing video however I would like to see more advanced topics such as load balancing. I would also be interested in seeing if HA Proxy can do pre authentication using local passwords on PF or against Active Directory.

  • @conrat2000
    @conrat2000 2 года назад +1

    Thank you so much!

  • @Dorff_Meister
    @Dorff_Meister Год назад

    I've just setup Nginx Proxy Manager (NPM) in a docker container, have it all working, and am in the process of copying the hosts from my HAProxy config (provided by pfsense) to NPM. I'm finding NPM a lot faster to add and manage the configuration. Hopefully I don't find issues or loss in functionality (I'll run the concurrently at least for a while).

  • @stefanmilev1
    @stefanmilev1 4 года назад

    Great video Lawrence, I always wanted to setup something like this on my pfsense server as I was annoyed with the certificate message popping up all the time. Now using your guide I will try to set it up and make mi network a bit better.

  • @superzeiberman9811
    @superzeiberman9811 3 года назад

    Who gives a thumb down for this video? It's a very infomative video and nice structured!

  • @manutech156
    @manutech156 3 года назад +1

    Are you going to do a video on how to setup Dynamic DNS with digitalOcean and pfSense?

  • @NoRogeR
    @NoRogeR 3 года назад +1

    Great video 👍 I would suggest to turn on xforwardedfor as well to reveal real ips to backends

  • @rnovachkov
    @rnovachkov 2 года назад

    PLEASE make a video how to setup pfsense with haproxy and synology behind with all the services working.

  • @kapurar
    @kapurar 2 года назад +1

    Great video!

  • @annoyedbybrother
    @annoyedbybrother Год назад

    If you are using cloudflair you need to make sure you set Your SSL/TLS encryption mode to "Full". this is under Domian > SSL/TLS > Overview

  • @RichardBuckerCodes
    @RichardBuckerCodes 4 года назад +2

    what about backend machines that need to generate valid certs

  • @furfoxsake
    @furfoxsake 3 года назад +1

    Awesome video, I was able to get it working for WAN connections. But for some reason when I try to connect from the LAN side, it redirects me to the pfSense login page. An thoughts on why this is happening?

  • @alpachino468
    @alpachino468 Год назад

    I wasn't able to get through the entire video yet. Is there any mention of how to stop people from outside your network accessing certain proxies? Basically, I don't want to let people outside my local network access TrueNAS.

  • @saywhat9158
    @saywhat9158 4 года назад

    Great timing ... thanks for this info. Now, if pfsense would unify the Captive Portal login/logout window like Opnsense instead of using an archaic method of popup windows that most browsers disable by default due to security issues, then I might actually purchase a licensed Netgate box from them when I upgrade for hardware AES support.

  • @masterhinz
    @masterhinz 3 года назад

    That was so helpfull. Thanks a lot for this great video!

  • @udbytossen
    @udbytossen 3 года назад +1

    Hi Lawrense system.
    Great Video - Although I want to use this before our Company Webserver - but how about getting the tracking information. I located a option under frontend - "Use forwardfor" option, for statestic etc on websites - But this guide works fine, and adding this option stills shows the client IP as 192.168.1.1 (PFsense) - so how can I make my marketingguy happy :-)
    Keep them Videos Coming - like the late evenings with those!

  • @whatevah666
    @whatevah666 2 года назад

    awsome vid, thanks. small nitpicking, you don HAVE TO have a default backend as stated in the fw "If a backend is selected with actions above or in other shared frontends, no default is needed and this can be left to "None"." I prefer not having a default backend in case of scanners etc, that way you don't "leak" info via certificated and such, it just seems better to me :)

    • @BorisJohnsonMayor
      @BorisJohnsonMayor Год назад

      What about the default certificate for the frontend. It requires one, so is it a problem?

  • @VioletDragonsProjects
    @VioletDragonsProjects 4 года назад

    ive finally got this working on two domains. Cloud and Web Server behind two domains i now have to setup mail. but there is some differences in my lab than in this video. You didnt mention about VIP/Virtual IPs it will work without it just wont be able to have this setup internally only externally but yeah it works took some setting up to do. Web Servers requires some tweaking for http to https redirection Wordpress Servers on the other hand requires a lot of tweaking or web site is broken i.e layout.

  • @godyK
    @godyK 2 года назад

    I Have followed the video but I am having one problem whenever I try to access the sites I get redirected to the HAProxy stats page on all the domains

  • @PeraLimar
    @PeraLimar 4 года назад +1

    Great, thank you.

  • @tac73
    @tac73 3 года назад

    I've got to be honest here. The only thing I know for sure that I've learned is, that your speech is way faster than my brain can process. I've replayed segments over and over, til I'm just worn out. I hope I don't lose interest before it all sinks in! :-)

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад +1

      Use the RUclips slow speed playback option

    • @tac73
      @tac73 3 года назад

      @@LAWRENCESYSTEMS That's actually a very good idea! Thanks Tom!

  • @william7950
    @william7950 4 года назад +1

    man, thanks a lot for that

  • @WebbedPete
    @WebbedPete 3 года назад

    KEY item missing: to do this on the LAN side, in System->Advanced, set a different TCP port, AND check "Disable webConfigurator redirect rule" Then HAproxy can listen to 443 on the LAN side of pfSense.

  • @jim7smith
    @jim7smith 3 года назад

    What software are you using at the beginning with the image of the network?

  • @fbifido2
    @fbifido2 4 года назад +2

    Would a wildcard domain certificate using ACME DNS auth, work in these case as seen in your video?

    • @manthing1467
      @manthing1467 4 года назад

      I am trying that right now but ive been dealing with 503 errors w the SSL going through.

  • @georgelza
    @georgelza Год назад

    ... hi hi.
    I have my pfSense setup current to work with CloudFlare and using a lets encrypt cert.
    due to various reasons I need to change my domain. I already bought the new domain from Google and already created/added it to my CF profile and updated the domain on google's side to use the CF NS's.
    know this is prob a bit of the beaten track, but any chance you can do a video... showing whats additional to be added or changed to accommodate this use case.

  • @ramikilany9279
    @ramikilany9279 4 года назад

    About the Pure NAT it is not working with me, I did the same configuration but the internal IP does not open the WAN IP, where is the problem in your opinion? Best Regards

  • @ramhee98
    @ramhee98 4 года назад

    really helpfull video man ;)

  • @bdorr17
    @bdorr17 4 года назад +1

    Hey, it looks like the correct command would be /usr/local/etc/rc.d/haproxy.sh restart which I think you left out. Just want to confirm that

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 года назад

      Do it's in the documentation not what I say..lol

    • @bdorr17
      @bdorr17 4 года назад

      @@LAWRENCESYSTEMS lol no issues, just in case you use that function though, might want to double check

  • @mohsinhassan88
    @mohsinhassan88 4 года назад +2

    Great Video, I have been searching for a video like this forever as i was trying to set this up for myself.
    i have been watching your videos for a long time and am a huge fan.
    I do have a comment about the flow of the video, while i was able to understand what you were talking about since i spent a long time reading up on this topic, i feel compared to your previous video on other topics (which are excellent as a follow along and very well structured even for someone completely new) I feel this was not as well structured.
    I mean the content excellent, it just need a bit more introduction and preface before you got into the meat of things.
    More along the lines, why one would need this, what alternatives are available out there.
    Most of your videos before you get started with the topic you explain what the topic is, what alternatives are available (which i love because then i can go out and read up on those topics as well and is a great way of learning new things.
    Maybe do another video just talking about those points before we start watching this video.
    Nonetheless this is an excellent video. keep it up.

  • @house0795
    @house0795 Год назад

    Can I set reverse proxy but only for local use not open to internet with haproxy ?

  • @ranjithgreen
    @ranjithgreen 3 года назад

    thank you

  • @misckicirina
    @misckicirina 2 года назад

    Great tutorial, thank you. I followed it and HA Proxy works in my PfSense but unfortunately only if I disable pfBlockerNG and DNSBL. Maybe this is caused by the two NAT rules created by pfBlockerNG that forward ports 80 and 443 to 8081 and 8443, respectively. Is there any way to get HA Proxy working with pfBlockerNG enabled? Or should I replace pfBlockerNG with Pinhole?

  • @jeremyrangel8138
    @jeremyrangel8138 3 года назад

    is this the same process we could use if we wanted multiple web servers with only one public IP address?

  • @danielday8828
    @danielday8828 4 года назад

    Was wondering if you could elaborate on doing a redirect rule from http to https?

  • @ranjithgreen
    @ranjithgreen 3 года назад

    Thank you for wonderfully video, i am facing issue i want to use my domain without 'www' i tried but not resolved and shows (503 Service Unavailable
    No server is available to handle this request.) i need help in this with Haproxy and domain configuration, once again thank you

  • @MrBaracas
    @MrBaracas 3 года назад

    Would this work for those origin certs that cloudflare trys like heck to get its people to use?

  • @benek9841
    @benek9841 2 года назад

    Hi Lawrence, great video as always. Yours videos inspired me to build my Pfsense router. Now I migrated my Nginx to HAproxy. Question: is there a way to do some basic authentication to some back end services?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      Generally auth is taken care of by the app you are running

  • @PhrozenN
    @PhrozenN 4 года назад +1

    How the hell did you get your terminal looking like that? Thx for the great tutorials :)

    • @chwaee
      @chwaee 4 года назад +1

      parrot OS

    • @PhrozenN
      @PhrozenN 4 года назад

      @@chwaee what? No. That's pop os

    • @lepsycho3691
      @lepsycho3691 4 года назад

      He asked for the terminal not the distro. If i'm not mistaking this is zsh and you can use it on any distro.

  • @ChrisVogtmann
    @ChrisVogtmann 3 года назад

    Are there firewall rules that need to be setup?
    I have a mail server on the LAN and tried to follow this to add a cert so I could have it behind an ssl but port 80 still works fine but when I go to 443 I get PR_CONNECT_RESET_ERROR
    When I run the terminal command, it shows it sending the cert for my domain set up in acme
    Any Ideas?

  • @faizmustofa6369
    @faizmustofa6369 2 года назад

    what that all domain is private network ? or public

  • @Tom-jo8fu
    @Tom-jo8fu 7 месяцев назад

    How to setup cloudflare localdns? I received constant an ssl error.

  • @frankihk
    @frankihk 4 года назад

    hi Lawrence, how to setup snort protection for each sub domain or acl

  • @weismichael
    @weismichael 4 года назад

    thanks for the video, as ur a professional for unifi products, u can maybe tell me, how to make unifi nvr get working through haproxy. the ui is running on port 7443, but it also needs port 7446 for the video stream. i am not able to get it running. maybe u have an advice.

  • @ranjithgreen
    @ranjithgreen 3 года назад

    i need help in this with Haproxy redirect non-www domains to their www variant once again thank you

  • @johnglennan2153
    @johnglennan2153 2 года назад

    I'm getting DNS rebinding attack detected after setting up the HA-Proxy Part then testing the domain I registered. (EDIT) I ended up solving this by enabling HA Proxy. Sorry for this comment awesome video. You rock! Also do you need open vpn still if you use HA Proxy?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      Putting things behind a VPN is a more secure method.

  • @Jeancomputech
    @Jeancomputech 2 года назад

    Hi Tom i hope you are having a great Saturday. The question i have is do you have have to do port forwarding to the backend server or just added to the proxy backend?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      No, you allow ports to HAProxy, not to the servers behind it.

  • @Gillis785
    @Gillis785 4 года назад

    Hi there just wondering if there is something you need to add in your nginx conf file to make this work. It works fine when running apache but I get error 503 Service Unavailable when running nginx. Thank you.

  • @koenpauwels98
    @koenpauwels98 3 года назад

    Great tutorial, sometimes its a little bit over my head.. im not really an IT guy, but i wanted to achieve this. So some stuff you just assume you should know :D but i dont

  • @simonlock9718
    @simonlock9718 4 года назад +1

    Hi Lawrence. Please could you make a video showing how to use haproxy (HTTPS) for local only servers. E.g. FreeNAS. I have several local only servers and each are configured using certbot to obtain their own certificates (cloudflare dns challenge). I know that you hinted at NAT reflection / Pure NAT but I simply cannot get this to work. Thanks

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 года назад +1

      Already did ruclips.net/video/jpyUm53we-Y/видео.html

    • @simonlock9718
      @simonlock9718 4 года назад

      Thank you Lawrence. I had to use a VIP to get it working.@@LAWRENCESYSTEMS

  •  4 года назад +1

    One of the best out there how you should enplane for a newbie that have hard time to see the connections for functions. you doing well for add extra information in some impotent points. I have a wish do. Certificate is a brain eater for me to get everything together what exactly every type of file doing and are fore.
    Some common words when talking certificate.
    Ca ?
    Root ?
    Public cert ?
    chain ?
    Generate self sign cert?
    x509?
    Validation ?
    Best way to storing Certificate, root,cert,ca or what they are?
    Key ?? This is weird thing to understand. sometimes there is Key file with certificate.
    Dose the Country Code,location,Email Address, city...... importen/or dangerous in some way?

  • @amaze646
    @amaze646 4 года назад

    Tnx man!

  • @manmustbuild
    @manmustbuild 2 года назад

    I've got my front end set to listen on LAN address. Prefer to get that working before I open up the WAN ports. pfsense has a valid ACME wildcard cert and the subdomain resolves and that's all working great. But whenever I try to turn on HAProxy and route to a different internal server, I lose access to the pfsense webGUI.

  • @freiermuthj
    @freiermuthj 4 года назад

    I swear... every PFSense video

  • @androbourne
    @androbourne 2 года назад

    If you are using certs locally on the host do you still need SSL Offloading? How can that be done without needing 2 certs? Aka cert from PFSense and locally issused cert from Lets Encrypt on local server?
    I basically just want HAProxy to pass whatever cert is already assigned on the server its self. I don't want HAProxy to manage any certs.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      There might be a way to do that, but I made the tutorial based on the more common way people use it which is having HAProxy handle the certs.

  • @Mr.Leeroy
    @Mr.Leeroy 4 года назад

    Instead of skipping SSL checks for self-signed certs on backends it would be nice to make HAProxy honor their self-signed CA.

  • @ITWorksSoftware
    @ITWorksSoftware 2 года назад +1

    I appreciate the tutorial, butwish you could do it step by step from start to finish. So lost right now.

  • @codochi
    @codochi 4 года назад

    Hi~
    How to configure synology + directadmin same port 443? I tried but it only run synology.

  • @pixel9119
    @pixel9119 3 года назад

    what do I have to put in my txt record on the dns server?

  • @PierRafiq
    @PierRafiq 2 года назад

    Bonjour ,,, Great

  • @charlie7975
    @charlie7975 4 года назад

    Great video. All of yours are great. I want to make sure WAN traffic to my pfSense login and a couple other web servers gets blocked so access is only local/VPN. Can you point me in the right direction?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 года назад

      the pfsense web configuration page is blocked on WAN by deafult.

  • @emilianocaballero7013
    @emilianocaballero7013 Год назад

    Just making sure, can this be used to provide a let's encrypt certificate to an internal PBX server such as FreePBX?

  • @moondawson2165
    @moondawson2165 2 года назад

    Hi Tom, which of digitalocean solutions supports let's encrypt?

  • @gt_masterman
    @gt_masterman Год назад

    why exactly is it a bad idea to expose your NAS? wouldn't this be one of the applications as it lets me access my files from anywhere? and since the NAS has its own login, there shouldn't be any way to access data if you aren't authorized right?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Год назад

      In theory yes, in reality if there is a security flaw, which has happened many times, then others can access your files, delete them, or encrypt them and charge a ransom.

  • @frankihk
    @frankihk 4 года назад

    it is possible deploy with openvpn?

  • @Napert
    @Napert Год назад

    Where can I find a tutorial for this but with cloudflare and without exposing to public internet?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Год назад

      If you are talking about Cloudflare tunnels, that does expose it to the public internet.

  • @vasquezmi
    @vasquezmi Год назад

    How are you able to passthrough your public IP to the WAN interface? What I see on the front end is the same public IP that you set in Digital Ocean. For me I only see the IP assigned by my cable modem. Is there an option to set that or pass it through?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Год назад

      I think what you are looking for is In the back end settings "Use Client-IP to connect to backend servers."

    • @vasquezmi
      @vasquezmi Год назад

      @@LAWRENCESYSTEMS I think I understand now as I look through the steps. I have a BYOD cable modem that is set to router mode. I believe I need to set it to Bridge mode in order to have the public IP passthrough to the pfSense....or use like you said the Client-IP / 1:1 NAT options that are available.

  • @royhall4649
    @royhall4649 4 года назад

    I have followed this step by step, but none of my web servers are working...

  • @AntonKristensen
    @AntonKristensen 3 года назад

    Any chance you have or could make a video showing how to do this with tls / https mode, to route to servers depending on the certificates sni over tls/https and not the http/https you have there. Best regards!

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад

      Just change the mode, it's a settings option.

  • @FabioVascoGomes
    @FabioVascoGomes 4 года назад

    No Join button on this channel?

  • @homeassistantiptv8068
    @homeassistantiptv8068 3 года назад

    my haProxy has stopped working as soon as i configured LAGG - haproxy sites now only work via WAN and not on the LAN.. WOuld anyone be able to point me in the right direction?

  • @nanabkgyasi
    @nanabkgyasi 2 года назад

    Hey Lawrence. Is there a way for me to edit the haproxy config file? My nginx is failing to start because the ssl certificate is not where it expects it although hapxy/acme is issuing it successfully.

  • @FTLN
    @FTLN 2 года назад

    Hi Lawrence, I have a standalone PFSENSE in the cloud with one wan interface, one OPENVPN interface and One IPSEC interface, can you confirm from which interface is used by HA proxy to proxy the request ?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  2 года назад

      I have never tried that setup.

    • @FTLN
      @FTLN 2 года назад

      @@LAWRENCESYSTEMS Thanks, but from which interface does HA proxy forward traffic?

  • @garrettdengler7599
    @garrettdengler7599 3 года назад

    If I’m using a UniFi router, would this still work for me if I set up a pfsense box internally? Or would there be a better solution for that scenario?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад

      It would add more complexity that just replacing the UnFi router.

    • @garrettdengler7599
      @garrettdengler7599 3 года назад

      @@LAWRENCESYSTEMS Bummer. I can't justify replacing the udm-pro so I'll have to dig around for a different solution. Great video though. Thanks!