Re: DNS resolution problem since 1.8.14

2018-12-23 Thread Jonathan Matthews
eader X-Real-IP %[src] > > compression algo gzip > compression type text/css text/html text/javascript > application/javascript text/plain text/xml application/json > > # Forward to the main linked container by default > default_backend www > > > Any idea what is happening? I've tried to increase the DNS resolve timeout > to 5s and it didn't help. My feeling is that the newer versions of haproxy > cannot talk with the DNS provided by docker. > > Thanks > > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Http HealthCheck Issue

2018-12-19 Thread Jonathan Matthews
On Wed, 19 Dec 2018 at 19:23, UPPALAPATI, PRAVEEN wrote: > > Hmm. Wondering why do we need host header? I was able to do curl without the > header. I did not find anything in the doc. "curl" automatically adds a Host header unless you are directly hitting an IP address.

Re: Http HealthCheck Issue

2018-12-18 Thread Jonathan Matthews
elp in finding the error hidden in that log line, or can you manage to fix it? All the best, Jon -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: HA-Proxy configuration

2018-10-10 Thread Jonathan Matthews
is already set up as a supplier inside Wipro's procurement system. Do get in touch if the routes I've mentioned above don't meet your needs :-) All the best, Jonathan -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Need Clarification

2018-08-21 Thread Jonathan Matthews
On Tue, 21 Aug 2018 at 17:53, Jordan Finsbel wrote: > Hello my name is Jordan Finsbell and interested to get involved That's great! What areas are you interested in? J -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: HaProxy question

2018-08-10 Thread Jonathan Matthews
ed fine. >> >> I am not sure if I am being very clear in here but basically wanted to >> know if there is >> a way to do selective ssl offloading on the haproxy or bypass >> ssl offloading on the >> server that sits behind the proxy? This is required so that custom

Re: Regarding HA proxy configuration with denodo

2018-07-26 Thread Jonathan Matthews
ocurement system. Do get in touch if the routes I've mentioned above don't meet your needs :-) All the best, Jonathan > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Help with environment variables in config

2018-07-21 Thread Jonathan Matthews
-4:~$ export GRAPH_PORT=8182 > ubuntu@ip-172-31-30-4:~$ sudo haproxy -d -V -f /etc/haproxy/haproxy.cfg > > On Sat, Jul 21, 2018 at 3:26 AM Igor Cicimov < > ig...@encompasscorporation.com> wrote: > >> On Sat, Jul 21, 2018 at 7:12 PM, Jonathan Matthews < >> cont...@jpluscpl

Re: Help with environment variables in config

2018-07-21 Thread Jonathan Matthews
e *exporting* the envvars before asking a child process (i.e. haproxy) to use them. J > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Setting up per-domain logging with haproxy

2018-07-17 Thread Jonathan Matthews
gth" parameter: http://cbonte.github.io/haproxy-dconv/1.8/configuration.html#3.1-log As the docs say: some syslog servers allow messages >1024, some don't. Use one that does :-) Cheers, Jonathan -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Need Help!

2018-06-26 Thread Jonathan Matthews
You may not have had many replies as your email was marked as spam. You might want to address this by, amongst other things, using plain text and not HTML. On 24 June 2018 at 18:32, Ray Jender wrote: > I am sending rtmp from OBS with the streaming set to rtmp://”HAproxy server > IP”:1935/LPC1

Re: [PATCH] REGTEST: stick-tables: Test expiration when used with table_*

2018-06-21 Thread Jonathan Matthews
alid as a TLD. Perhaps missing.haproxy.invalid for when a DNS entry needs not to exist, and ... something else for when it needs a real backend? I'm out of ideas on that 2nd use case ... J > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: [Feature request] Call fan-out to all endpoints.

2018-06-10 Thread Jonathan Matthews
On 10 June 2018 at 08:44, amotz wrote: > I found myself needing the options to do "fantout" for a call. Meaning > making 1 call to haproxy and have it pass that call to all of the endpoint > currently active. > I don't mind implementing this myself and push to code review Is this a > feature you

Re: JWT payloads break b64dec convertor

2018-05-28 Thread Jonathan Matthews
On Mon, 28 May 2018 at 14:26, Willy Tarreau <w...@1wt.eu> wrote: > On Mon, May 28, 2018 at 01:43:41PM +0100, Jonathan Matthews wrote: > > Improvements and suggestions welcome; flames and horror -> /dev/null ;-) > > Would anyone be interested in adding two new conver

Re: JWT payloads break b64dec convertor

2018-05-28 Thread Jonathan Matthews
On 28 May 2018 at 12:32, Jonathan Matthews <cont...@jpluscplusm.com> wrote: > I think with your points and ccripy's sneaky (kudos!) padding > insertion, I can do something which suffices for my current audit > needs. For the list, here's my working v1 that I ended up with. I'm sure

Re: JWT payloads break b64dec convertor

2018-05-28 Thread Jonathan Matthews
On 28 May 2018 at 09:19, Adis Nezirovic <aneziro...@haproxy.com> wrote: > On 05/26/2018 04:27 PM, Jonathan Matthews wrote: >> Hello folks, >> >> The payload (and other parts) of a JSON Web Token (JWT, a popular and >> growing auth standard: https://tools.ietf.org/h

JWT payloads break b64dec convertor

2018-05-26 Thread Jonathan Matthews
Hello folks, The payload (and other parts) of a JSON Web Token (JWT, a popular and growing auth standard: https://tools.ietf.org/html/rfc7519) is base64 encoded. Unfortunately, the payload encoding (specified in https://tools.ietf.org/html/rfc7515) is defined as the "URL safe" variant. This

Re: WAF with HA Proxy.

2018-05-09 Thread Jonathan Matthews
". Does it integrate with HAProxy? Via what mechanism? J > <https://www.signalsciences.com/waf-web-application-firewall/> > <https://www.signalsciences.com/waf-web-application-firewall/> > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Use SNI with healthchecks

2018-04-24 Thread Jonathan Matthews
; On 23 April 2018 at 16:38, GALLISSOT VINCENT <vincent.gallis...@m6.fr> > wrote: > > Does anybody know how can I use healthchecks over HTTPS with SNI support > ? > > You need haproxy 1.8 for this, it contains the check-sni directive > which allows to set SNI to a specific string for the health check: > > http://cbonte.github.io/haproxy-dconv/1.8/configuration.html#5.2-check-sni > > > > > Regards, > > Lukas > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Version 1.5.12, getting 502 when server check fails, but server is still working

2018-04-16 Thread Jonathan Matthews
n possibly upgrade to 1.6 or later, I suspect the frequency of answers you get and the flexibility they'll have to help you will improve markedly. HTH! J -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: resolvers - resolv.conf fallback

2018-04-14 Thread Jonathan Matthews
On 14 April 2018 at 05:13, Willy Tarreau wrote: > On Fri, Apr 13, 2018 at 03:48:19PM -0600, Ben Draut wrote: >> How about 'parse-resolv-conf' for the current feature, and we reserve >> 'use-system-resolvers' for the feature that Jonathan described? > > Perfect! "parse" is quite

Re: resolvers - resolv.conf fallback

2018-04-13 Thread Jonathan Matthews
esolv.conf over time. AIUI this will actually parse once, at proxy startup, which I suggest should be made more obvious in the naming. If I'm wrong, or splitting hairs, please ignore! J > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Health Checks not run before attempting to use backend

2018-04-13 Thread Jonathan Matthews
gt; I asked about this in 2014 ("Current solutions to the soft-restart-healthcheck-spread problem?") and I don't recall seeing a fix since then. Very interested in whatever you find out! J > -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Logs full TCP incoming and outgoing packets

2018-04-09 Thread Jonathan Matthews
On 10 April 2018 at 00:04, wrote: > Hello everybody, > > For an application, I use haproxy in TCP mode but I would need to log, from > the main load balancer machine, all the TCP transactions (incoming packets > sent to the node then the answer that is sent back from the

Re: New HTTP action: DNS resolution at run time

2018-03-17 Thread Jonathan Matthews
On 30 January 2018 at 09:04, Baptiste wrote: > Hi all, > > Please find enclosed a few patches which adds a new HTTP action into > HAProxy: do-resolve. > This action can be used to perform DNS resolution based on information found > in the client request and the result is stored

Re: skip logging some query parameters during GET request

2018-03-13 Thread Jonathan Matthews
xy to exclude one specific query parameters on a GET > request? > > the request: > > GET /api?username=seriously=ohnoes=locate=chocolat > > desired log something like: > > GET /api?username=seriously=locate=chocolat > > I can do this downstream in rsyslog but I'd p

Re: BUG/MINOR: limiting the value of "inter" parameter for Health check

2018-03-07 Thread Jonathan Matthews
. What's the rationale for having *any* maximum value here - saving folks from unintentional misconfigurations, or something else? J -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Active-Passive HAProxy Issue enquiry

2018-02-15 Thread Jonathan Matthews
On 15 February 2018 at 10:08, Swarup Saha wrote: > Hi, > I need help from HAProxy organization. Hello there. This is the haproxy user mailing list. It is received and read by a wider range of users across the world, many of whom read it in an individual capacity. If you want

Re: How can I map bindings to the correct backend?

2018-01-25 Thread Jonathan Matthews
Unless I'm missing something, wouldn't you be rather better off just having a dedicated frontend for each set of ports that forwards to each distinct backend server? Or are you doing this at webscale, or something? :-) J -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: cannot bind socket - Need help with config file

2018-01-11 Thread Jonathan Matthews
On 11 January 2018 at 00:03, Imam Toufique wrote: > So, I have everything in the listen section commented out: > > frontend main >bind :2200 >default_backend sftp >timeout client 5d > > > #listen stats > # bind *:2200 > # mode tcp > # maxconn 2000 > #

Re: cannot bind socket - Need help with config file

2018-01-08 Thread Jonathan Matthews
940 (1416) : Starting proxy stats: cannot bind socket [ > 0.0.0.0:22] > I would strongly suspect that the server already has something bound to port 22. It's probably your SSH daemon. You'll need to fix that, by dedicating either a different port or interface to the SFTP listener. J > -

Re: haproxy without balancing

2018-01-05 Thread Jonathan Matthews
ipedia.org/wiki/Server_Name_Indication#Support) would be something worth checking, but as a datapoint I've not bothered supporting non-SNI clients for several years now. All the best, J -- Jonathan Matthews London, UK http://www.jpluscplusm.com/contact.html

Re: Poll: haproxy 1.4 support ?

2018-01-02 Thread Jonathan Matthews
On 2 January 2018 at 15:12, Willy Tarreau wrote: > So please simply voice in. Just a few "please keep it alive" will be > enough to convince me, otherwise I'll mark it unmaintained. I don't use 1.4, but I do have a small reason to say please *do* mark it as unmaintained. The

Re: Why HAProxy is not a web server?

2017-11-28 Thread Jonathan Matthews
On 27 November 2017 at 01:09, wrote: > Why HAProxy is not a web server? Because it's a load balancer. It talks to multiple other web servers, often called backends or origins, which provide the content for it to serve to consumers. HTH, J

Re: Tagging a 1.8 release?

2017-10-23 Thread Jonathan Matthews
On 20 October 2017 at 17:17, Willy Tarreau wrote: > I'd like to collect all the pending stuff by the end of next week and issue > a release candidate. Don't expect too much stability yet though, but your > tests and reports will obviously be welcome. Are you still finger-in-the-air

Re: counters for specific http status code

2016-07-12 Thread Jonathan Matthews
On 12 Jul 2016 05:43, "Willy Tarreau" wrote: > That could possibly be ssh $host "halog -st < /var/log/haproxy.log" or > anything like this. On behalf of people running busy load balancers / edge proxies / etc, please don't do this ;-) Instead laptop$ halog -st <(ssh -C $balancer

Re: AWS ELB with SSL backend adds proxy protocol inside SSL stream

2016-05-10 Thread Jonathan Matthews
*inside* Cloud Foundry, for the record :-) As an aside, I'd be interested in even a brief summary of how/if you resolved your problem, given that I've not seen it described on the list before. I wonder if you're the first to run into this specific problem ... All the best, Jonathan -- Jonathan Ma

Re: Erroneous error code on wrong configuration.

2016-05-01 Thread Jonathan Matthews
On 29 Apr 2016 11:29, "Mayank Jha" wrote: > > I am facing the following in haproxy 1.5. I get the following error, with error code "SC" which is very misleading, for the below mentioned config. Why do you think it's misleading? > haproxy[6379]: 127.0.0.1:53010

Re: unique-id-header set twice

2016-04-30 Thread Jonathan Matthews
On 29 Apr 2016 06:55, "Willy Tarreau" wrote: > > On Fri, Apr 22, 2016 at 04:37:04PM +0200, Erwin Schliske wrote: > > Hello, > > > > for some of our services requests pass haproxy twice. As we have set the > > global option unique-id-header this header is added twice. [snip] > > I

Re: Dynamic backend routing base on header

2016-01-18 Thread Jonathan Matthews
On 17 January 2016 at 17:54, Michel Blanc wrote: > Dear all, > > I am trying to get haproxy routing to a specific server if a header > (with the server nickname) is set. Can you adapt http://blog.haproxy.com/2015/01/26/web-application-name-to-backend-mapping-in-haproxy/ to

Re: SSL and Piranha conversion

2015-09-08 Thread Jonathan Matthews
On 8 Sep 2015 20:07, "Daniel Zenczak" wrote: > > Hello All, > > First time caller, short time listener. So this is the deal. My organization was running a CentOS box with Piranha on it to work as our load balancer between our two web servers. Well the

Re: SSL and Piranha conversion

2015-09-08 Thread Jonathan Matthews
On 8 September 2015 at 20:56, Daniel Zenczak wrote: > Hello Jonathan, > > Thank you for the response. That old gateway workstation is > not going to be used anymore (the HDDs failed on it and the RAID board > didn’t warn/detect/tell us when it happened).

Re: How to profile stats web page users

2015-04-09 Thread Jonathan Matthews
I think you want ACL-driven stats scope statements, which don't exist to the best of my knowledge. In your case, rather than open a bunch of different ports, I'd give people different FQDNs to hit, and point a wildcard DNS record at a single port 80. (Well, a :443 with TLS, if I were doing it,

Re: How to profile stats web page users

2015-04-09 Thread Jonathan Matthews
Have you looked at stats scope? https://cbonte.github.io/haproxy-dconv/configuration-1.5.html#stats%20scope Jonathan

stats uri doesn't inherit from defaults sections

2015-04-09 Thread Jonathan Matthews
. I've only tested this on the latest Debian backports version, 1.5.8, but I don't see anything related in the changelog since then which makes me think it's been fixed. The docs for 1.5.11 currently state it's a defaults-settable config statement. Cheers, Jonathan -- Jonathan Matthews Oxford

Re: Gracefull shutdown

2015-04-05 Thread Jonathan Matthews
On 5 April 2015 at 10:33, Cohen Galit galit.co...@comverse.com wrote: How can I perform a graceful shutdown to HAProxy? I mean, not by killing process with pid. Please could you describe the behaviours you expect from a graceful shutdown which you don't get from killing the process? I would

Re: Environment variable in port part of peer definition not resolved

2015-03-25 Thread Jonathan Matthews
On 25 March 2015 at 23:14, Dennis Jacobfeuerborn denni...@conversis.de wrote: Hi, I'm trying to make the haproxy configuration more dynamic using environment variables and while this works for the definition of the pid file and the stats socket when I try to use an env. variable as the port

Re: Debian (wheezy) official backport stuck at 1.5.8?

2015-03-12 Thread Jonathan Matthews
On 10 March 2015 at 16:36, Vincent Bernat ber...@luffy.cx wrote: ❦ 10 mars 2015 15:48 GMT, Jonathan Matthews cont...@jpluscplusm.com : http://backports.debian.org/wheezy-backports/overview/ reports that it's up to date with 1.5, but is only making 1.5.8 available. Does anyone have any

Debian (wheezy) official backport stuck at 1.5.8?

2015-03-12 Thread Jonathan Matthews
Hi all - http://backports.debian.org/wheezy-backports/overview/ reports that it's up to date with 1.5, but is only making 1.5.8 available. Does anyone have any insight into why this might be and how/if one might help the situation? Cheers, Jonathan

Re: How to compare two haproxy.cfg files?

2015-03-09 Thread Jonathan Matthews
On 8 March 2015 at 18:46, Tom Limoncelli tlimonce...@stackexchange.com wrote: The first step is to put the sections in a fixed order: First general, the defaults, then each listen/frontend/backend sorted by name. That works fine and has been a big help. Not a huge amount of help with your

Re: Sharing configuration between multiple backends

2015-03-09 Thread Jonathan Matthews
On 9 March 2015 at 00:12, Thrawn shell_layer-git...@yahoo.com.au wrote: Hi, all. Is there a way to share configuration between multiple backends? The use case for this is that we would like to configure different response headers for different parts of our application, based on the request

Re: Config reload to take out backend server still getting traffic

2014-12-11 Thread Jonathan Matthews
On 11 December 2014 at 07:58, Kasim ktu...@gmail.com wrote: Hi, I am running haproxy on Ubuntu 14.04. After I added following config: stick-table type ip size 2m expire 5m stick on src Taking out a server and reloading haproxy still sends traffic to that server ever after the stick table

Re: 1.5.9 crashes every 4 hours, like clockwork

2014-12-11 Thread Jonathan Matthews
On 11 Dec 2014 14:27, David Adams dr...@yahoo.com wrote: We are running 1.5.9 on Centos 6.5. It crashes 10 seconds (give or take a few seconds) after 1am, 5am, 9am, 1pm, 5pm and 9pm, like clockwork; let's call that CRASHTIME. Previously we'd been using 1.5.3 on the same hardware for some

Re: Can not set or clear a table when the Key contains \

2014-12-08 Thread Jonathan Matthews
On 5 December 2014 at 07:05, Nick chengcheng...@pdf.com wrote: when i try the command --echo -e set table RD01-CSN-1 key PVG\\PENGZ data.server_id 3 | socat /var/run/haproxy.stat stdio, the unix socket seems excluded the backslash \\, so i cannot successfully edit the Haproxy tables. the

Re: Disable HTTP logging for specific backend in HAProxy

2014-12-08 Thread Jonathan Matthews
On 7 December 2014 at 20:54, Alexander Minza alexander.mi...@gmail.com wrote: How does one adjust logging level or disable logging altogether for specific backends in HAProxy? In the example below, both directives http-request set-log-level err and no log seem to have no effect - the logs are

Re: Can't find an old example of haproxy failover setup with 2 locations

2014-12-08 Thread Jonathan Matthews
On 8 Dec 2014 15:10, Aleksandr Vinokurov aleksandr@gmail.com wrote: I've seen it 2 years ago. If I remember it right, Willy Tarreau was the author and it had ASCII graphics for network schema. It depicts step by step the configuration from one location and one server to 2 locations and 4

Re: Can't get HAProxy to support Forward Secrecy FS

2014-12-08 Thread Jonathan Matthews
On 8 December 2014 at 22:44, Sander Rijken san...@sanderrijken.nl wrote: System is Ubuntu 12.04 LTS server, with openssl 1.0.1 and haproxy 1.5.9 OpenSSL version OpenSSL 1.0.1 14 Mar 2012 I'm currently using the following, started with the suggested [stanzas][1] (formatted for

Re: Significant number of 400 errors..

2014-11-27 Thread Jonathan Matthews
On 27 November 2014 at 10:39, Alexey Zilber alexeyzil...@gmail.com wrote: That's part of what I'm trying to figure out.. where are the junk bytes coming from. Is it from the client, server, haproxy, or networking issue? That's what tcpdump is useful for. Use it at different places in your

Re: POST body not getting forwarded

2014-11-20 Thread Jonathan Matthews
On 20 November 2014 05:17, Rodney Smith rodney...@gmail.com wrote: I have a problem where a client is sending audio data via POST, and while the request line and headers reach the server, the body of the POST does not. However, if the client uses the header Transfer-Encoding: chunked and

Re: Haproxy - time to split traffic on servers

2014-11-14 Thread Jonathan Matthews
On 14 November 2014 22:59, Gorj Design ( Dragos ) gorjdes...@yahoo.com wrote: Hello, I have been using Haproxy to split the traffic between my servers. I have a haproxy server and 2 servers that receive the traffic using round robin . The traffic is split usually very good 50 % on one

Re: How can I force all frontend traffic to be temporarily queued/buffered by HAProxy?

2014-07-17 Thread Jonathan Matthews
On 17 Jul 2014 14:50, Abe Voelker a...@abevoelker.com wrote: So basically I'm wondering if there is a way to expire these pre-existing sessions or connections or somehow force them to behave like a new one so that they will queue up in HAProxy? I believe 1.5 has the on-marked-down

Re: Using a Whitlist to Redirect Users not on the Whitelist

2014-07-17 Thread Jonathan Matthews
On 17 Jul 2014 18:15, JDzialo John jdzi...@edrnet.com wrote: I am creating a whitelist of subnets allowed to access HAPROXY during maintenance. Basically I want to redirect everyone to our maintenance page other than users in the whitelisted file. This is not working and is forwarding everyone

Re: Adding Serial Number to POST Requests

2014-07-16 Thread Jonathan Matthews
On 16 Jul 2014 16:56, Zuoning Yin zuon...@graphsql.com wrote: We later also got the help from Willy. He provided us a configuration which solved our problem. To benefit other people, I just posted it here. I had meant to chime in on this thread earlier. What happens when your HAProxy layer

Re: Filing bugs.. found a bug in 1.5.1 (http-send-name-header is broken)

2014-07-07 Thread Jonathan Matthews
On 7 Jul 2014 14:44, Alexey Zilber alexeyzil...@gmail.com wrote: Hey guys, I couldn't a bug tracker for HAProxy, and I found a serious bug in 1.5.1 that may be a harbinger of other broken things in header manipulation. The bug is: I added 'http-send-name-header sfdev1' unde the

Re: haproxy 1.4 and ssl

2014-06-16 Thread Jonathan Matthews
On 16 Jun 2014 13:19, che...@nosuchhost.net wrote: hi all i have the following situation: i have 4 real servers (two exchange2013 and 2 citrix) which should get loadbalanced behind haproxy 1.4 (because this is the version shipped with redhat). this backendservers should talk: exchanges:

Re: HAProxy connection remains but web page stream is cut off prematurely

2014-05-19 Thread Jonathan Matthews
John, Willy already replied to your original thread. I suggest you engage with his detailed reply, there, instead of starting a new thread.

Recommended strategy for running 1.5 in production

2014-04-14 Thread Jonathan Matthews
Hi all - I've been running 1.4 for a number of years, but am pondering moving some as-yet-unreleased apps to 1.5, for SSL and ACL-ish reasons. I'd like to ask how you, 1.5 sysadmins and devs, track the development version, and how you decide which version to run in production. Do you just run

Re: Interaction between SSL and send-proxy

2014-03-26 Thread Jonathan Matthews
On 26 March 2014 11:01, Lukas Tribus luky...@hotmail.com wrote: Hi, Basic question on send-proxy: If the HAProxy server configuration has both SSL and send-proxy, should the proxy protocol header be sent encrypted within the SSL packet? Good question. In my opinion send_proxy should be

Current solutions to the soft-restart-healthcheck-spread problem?

2014-03-06 Thread Jonathan Matthews
Hi all - [ tl;dr How do you stop haproxy using failed backend servers immediately after reload? Haproxy devs, please consider implementing a consider-servers-initially-DOWN option! ] I wonder if people could outline how they're dealing with the combination of these two haproxy behaviours: 1) On

Re: how to disable/enable TCP_NODELAY soket option in TCP mode?

2014-02-07 Thread Jonathan Matthews
On 7 February 2014 08:29, Татаркин Евгений tatarkin@gmail.com wrote: I can`t find in haproxy documentation any information about Nagle`s algorithm or TCP_NODELAY option To quote http://marc.info/?l=haproxym=132173719731861w=2, which I discovered via searching

Re: Question about logging in HAProxy

2014-02-04 Thread Jonathan Matthews
On 4 Feb 2014 20:06, Kuldip Madnani k.madnan...@gmail.com wrote: Hi, I want to redirect the logs generated by HAProxy into some specific file .I read that in the global section in log option i can put a file location instead of IP address. I suspect (but can't confirm as I'm on a mobile

Re: How to write multiple config file in haproxy

2014-02-01 Thread Jonathan Matthews
On 1 February 2014 12:32, Sukanta Saha ss...@sprinklr.com wrote: Thanks for all your help, I will try, I have one more question that is about the haproxy.conf file , in this file we have written so many backends which are getting called from the frontends. Is there a way that I can seperate

Re: Question concerning stats server

2014-01-31 Thread Jonathan Matthews
On 31 January 2014 14:21, Andreas Mock andreas.m...@drumedar.de wrote: Hi all, I need a little help to understand how the html stats page can be accessed: How can I setup a stats page without having one backend? Is this possible? Do I have to provide a frontend too? This works for me:

Re: Haproxy as simple proxy forwarding each request

2014-01-29 Thread Jonathan Matthews
On 29 January 2014 17:59, Ricardo ri...@hotmail.com wrote: Hello, Is a bit mess situation but I can't configure Haproxy as a simple proxy. The behaviour I'm looking for is an Haproxy listen in port 80, receiving request to any url and forward each request to the appropiate domain trought

Re: HAProxy for Solaris 10 X86

2014-01-21 Thread Jonathan Matthews
On 21 January 2014 13:17, Vinoth M vinoth@ericsson.com wrote: Hi, 1) I am using Solaris 10 x86.Could you please let me know if there a pre compiled package available for it. 2) Also let me know if HAproxy is supported for Solaris 10 x86. I can't help with these 2 questions ...

Re: URL path in backend servers

2014-01-16 Thread Jonathan Matthews
Rakesh - I replied to your identical question about this, yesterday, suggesting what you could do to help yourself diagnose your problem. Please don't start new threads for the same question. Jonathan

Re: Forward request with the URL path

2014-01-15 Thread Jonathan Matthews
On 15 January 2014 07:36, Rakesh G K rgkj...@gmail.com wrote: Hello, Is it possible to forward an incoming request to the backend by retaining the URL path in http mode?. Using ACLs I was able to categorize the incoming requests to different rulesets, but on using a specific backend for a

Re: Tuning HAProxy for Production

2014-01-02 Thread Jonathan Matthews
On 2 January 2014 20:09, Jordan Arentsen jor...@bliss.io wrote: I'm trying to prepare HAProxy for a production, and I'm trying to figure out some good default configuration settings that will at least give me a good place to start. My main question revolves around the maxconn option and the

Re: disable backend through socket

2013-12-22 Thread Jonathan Matthews
On 22 Dec 2013 20:32, Patrick Hemmer hapr...@stormcloud9.net wrote: That disables a server. I want to disable a backend. No, you want to disable all the servers in a backend. I'm not sure there's a shortcut that's better than just doing them one by one. Others may be able to advise about

Replying to spam threads

2013-12-11 Thread Jonathan Matthews
My apologies to list members for replying to a spam thread and potentially screwing up mail classification at your end. My mistake. Jonathan

Re: performance problem about haproxy with libvirt20131201

2013-12-01 Thread Jonathan Matthews
archives to find information that's come up in the past on this exact topic. This list is archived in a few different places - once such place is here: http://marc.info/?l=haproxy Regards, Jonathan -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: RES: RES: RES: RES: RES: RES: RES: High CPU Usage (HaProxy)

2013-11-05 Thread Jonathan Matthews
On 5 November 2013 11:16, Willy Tarreau w...@1wt.eu wrote: It is a Xeon E5-2650 Dual (So we have 16 physical cores to use here and 32 threads). OK. Do you know if you have a single or multiple interrupts on your NICs, and if they're delivered to a single core, multiple cores, or floating

Re: HTTP and send-proxy

2013-10-29 Thread Jonathan Matthews
On 29 October 2013 08:30, Ge Jin altman87...@gmail.com wrote: Hi, Baptiste! Thanks for your reply, I found there is an incorrect configure in my ... email client? ;-)

Re: Haproxy for high load/High availability Mail Server on SSL

2013-10-12 Thread Jonathan Matthews
;-) Jonathan -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Redirect help

2013-10-07 Thread Jonathan Matthews
Have you tried searching online for the answer?

Re: HaProxy service usage

2013-10-04 Thread Jonathan Matthews
on this list. Regards, Jonathan -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Haproxy SSL certificat exception with root

2013-10-01 Thread Jonathan Matthews
that HAProxy can do to help here. Regards, Jonathan -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: HTTP Content-Check

2013-08-12 Thread Jonathan Matthews
://cbonte.github.io/haproxy-dconv/configuration-1.4.html#http-check expect Regards, Jonathan -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Major differences between 1.4 and 1.5

2013-07-25 Thread Jonathan Matthews
?) stick tables in as features. That stable/dev difference may decide it for you - it would for me in most circumstances. I'm sure more knowledgable people will chime in with more detailed comparisons. J -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Prevent HAProxy from toggeling back from fallback to primary

2013-07-23 Thread Jonathan Matthews
' health checks. I.e. several thousand (or whatever - do the mathS that makes sense for your situation) in the per-server rise setting: http://cbonte.github.io/haproxy-dconv/configuration-1.4.html#rise Cheers, Jonathan -- Jonathan Matthews Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Meaning of hrsp_2xx in show_stat

2013-06-12 Thread Jonathan Matthews
the lifetime of the HAProxy process. I don't think the 2 (rate counters) are directly comparable, and I'd definitely expect them to show different values. HTH, Jonathan -- Jonathan Matthews // Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Question about HTTP load balancing using HAProxy

2013-06-06 Thread Jonathan Matthews
, Jonathan -- Jonathan Matthews // Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: Question about HTTP load balancing using HAProxy

2013-06-03 Thread Jonathan Matthews
that HAProxy's sessions are related to the kind of in-request failure you seem to be concerned about. But I haven't run the current 1.5 development version, so I may be out of touch with what it does in this area. Regards, Jonathan -- Jonathan Matthews // Oxford, London, UK http

Re: Question about HTTP load balancing using HAProxy

2013-06-03 Thread Jonathan Matthews
extremely configurable health checks. If you've committed to solving this problem entirely, however, it will need more than just HAProxy. That's the sort of situation into which I normally step wearing my consultant hat, however, and charge you money ;-) Jonathan -- Jonathan Matthews // Oxford, London

Re: Meaning of hrsp_2xx in show stat

2013-05-30 Thread Jonathan Matthews
looking at it at a single point in time, but if you're trying to graph it, you might find it more useful to collect stot directly and calculate rates from that instead. Jonathan -- Jonathan Matthews // Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: smtpchk when using proxy protocol

2013-05-27 Thread Jonathan Matthews
something being tickled in the postfix code which replies with a multi-line response or if it doesn't understand PROXY messages entirely - I'm afraid I don't have any suggestions for fixing it. You might need to dig further and let us know what you find! HTH, Jonathan -- Jonathan Matthews // Oxford

Re: Redirect 1 time per day

2013-05-24 Thread Jonathan Matthews
suggest you start by looking at http://en.wikipedia.org/wiki/WURFL for a generic solution to this problem. I'm not sure if anyone has it integrated with HAProxy, however. Regards, Jonathan -- Jonathan Matthews // Oxford, London, UK http://www.jpluscplusm.com/contact.html

Re: HAProxy and MySQL failover

2013-05-16 Thread Jonathan Matthews
In the past I've used a ludicrously high setting on the primary for rise, the number of health checks it has to pass before it's considered to be up again. It's definitely a hack, though that's not to say I haven't used it in production ;-) Jonathan -- Jonathan Matthews Oxford, London, UK http

Re: Websockets and RTMP

2013-05-12 Thread Jonathan Matthews
in HAProxy 1.5. Jonathan -- Jonathan Matthews // Oxford, London, UK http://www.jpluscplusm.com/contact.html

Balancing SIP

2013-04-12 Thread Jonathan Matthews
Does anyone have anything they could share about using HAProxy for load-balancing SIP? Positive /or/ negative, of course! :-) Jonathan

  1   2   >