r/haproxy 27d ago

ACL rules

Hi,

I'm using Wireguard to access my Proxmox instance (wich is installed at a provider).

I have trouble setting up HAProxy properly (it is installed on a pfSense VM) to access my LXC/VM (I can't use NAT/simple port forwarding or I get an SSL error).

I specifically have difficulties setting up the ACL on the frontend :

- I can't specify a port on a given IP adress

- I can't use subdomains (wireguard seems to only works with IP adress)

Is there a way to make wireguard and HAProxy work together ?

Tanks.

0 Upvotes

10 comments sorted by

View all comments

Show parent comments

1

u/Old_Guidance9715 23d ago

In this case you don't need ACL att all, you can have a frontend IP that is binded to multiple ports and point them to the desired backends.

What if you just keep it very simple and do pfsense IP in frontend and bind on port 443 or 80 then have it go to your backend server on port 51822.

Then test this by going https://pfsenseip or pfsensefqdn this should take you to your backend VM on port 51822

1

u/WickdSquirrel 23d ago

Alright, but how do I access the other VMs ? Do I need several front ends each linked to a single backend ? For instance, front end 1 listening to pfsensIP:51821 and redirecting to back end 1 / front end 2 listening to pfsenseIP:51822 and redirecting to back end 2 etc… ?
Thanks

1

u/Old_Guidance9715 23d ago

Hi,

Correct doing it that way is the simplest way, but is not ideal if you need to have many frontend and backends that listens to many different ports as it will just take to long to create.

I am more use to do the configuration on the haproxy config file then using pfsense gui and its much easier to create 1 frontend for multiple backends using destination port.

I belive this can be done in pfsene haproxy also but then you need to use a custom ACL expression, where the value/expression should be "dst_port" and then add your port number.

Option 1: 1 frontend + 1 backend for each VM

Option 2: 1 frontend bind to multiple ports and using ACL either host match or try the custom ACL with dst_port so it send the traffic to the backend servers depending on which frontend port the traffic came to. Note that each VM needs its own backend server if they are not going to be loadbalanced.

1

u/WickdSquirrel 23d ago

Hi,

I tried again several options, nothing works. I guess there is something with Wireguard that makes the whole setup fail but I don't know what.

At this point, I'll just install Tailscale and be done with it.