# Request host on loadbalancer doesn't work as expected might I be doing something wrong?

**URL:** <https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453>\
**Category:** Rancher 1.x\
**Created:** [July 19, 2016, 12:11pm UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453 "2016-07-19T12:11:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zot24](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/zot24/32/1469_2.png) [@zot24](https://forums.suse.com/u/zot24)\
**Post date:** [July 19, 2016, 12:11pm UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453/1 "2016-07-19T12:11:55Z")

</div>

I got the following on my `docker-compose.yml` file:

```auto
ports:
    - 443:443/tcp
    - 5000:5000/tcp
  labels:
    io.rancher.loadbalancer.target.sslproxy: portus.my.domain:443=443
    io.rancher.loadbalancer.target.registry: registry.my.domain:443=443,5000=5000

```

I’m expecting to be able to request `https://registry.my.domain` and `https://registry.my.domain:5000` and be able to access to the `registry` container and at the same time be able to do `https://portus.my.domain` and access to the sslproxy container that will terminate SSL and connect to `portus` container.

I’m following the `Advance Load Balancer` rules on Rancher documentation trying to achieve this -\> [http://docs.rancher.com/rancher/latest/en/cattle/adding-load-balancers/#advanced-load-balancing-l7](http://docs.rancher.com/rancher/latest/en/cattle/adding-load-balancers/#advanced-load-balancing-l7) but I just can’t, am I doing something wrong? is this not the expected behavior when adding the \<REQUEST\_HOST\>?

Thanks

---

<div class="post-metadata">

**Author:** ![zot24](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/zot24/32/1469_2.png) [@zot24](https://forums.suse.com/u/zot24)\
**Post date:** [July 19, 2016, 12:52pm UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453/2 "2016-07-19T12:52:07Z")

</div>

As a temporary fix I’m just letting the `sslproxy` to redirect traffic from `registry.my.domain:443` to `registry.my.domain:5000` but that’s not what I want I don’t want to relay on that extra container just to redirect.

> Notice: that I don’t need SSL termination on the `registry` url what I want it’s be able query `registry.my.domain` as if I were querying `registry.my.domai:5000` and my registry have the `secure` flag turned on so it needs to be `https`

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [August 3, 2016, 5:27am UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453/3 "2016-08-03T05:27:48Z")

</div>

For every service specified on the load balancer, it is registered for every load balancer listening port.

So for your case, I think you’d need to add in a dummy routing rules

[http://docs.rancher.com/rancher/latest/en/cattle/adding-load-balancers/#examples-of-using-multiple-ports-in-advanced-routing-options](http://docs.rancher.com/rancher/latest/en/cattle/adding-load-balancers/#examples-of-using-multiple-ports-in-advanced-routing-options)

---

<div class="post-metadata">

**Author:** ![zot24](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/zot24/32/1469_2.png) [@zot24](https://forums.suse.com/u/zot24)\
**Post date:** [August 3, 2016, 7:11am UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453/4 "2016-08-03T07:11:54Z")

</div>

Thanks @denise!

My last question will be is it not possible to use the same ports? and just rely on the domain name to do the routing? like:

```auto
ports:
    - 443:443/tcp
  labels:
    io.rancher.loadbalancer.target.portus: portus.my.domain:443=443
    io.rancher.loadbalancer.target.registry: registry.my.domain:443=443

```

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [August 3, 2016, 8:04am UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453/5 "2016-08-03T08:04:11Z")

</div>

Only if you do SSL termination at the balancer so it can extract the HTTP Host header from the decrypted request.

(It is actually possible to do hostname routing for SSL requests without termination by looking at the SNI portion of the TLS handshake, but that is not supported yet. I think that made it into the new refractors balancer for 1.2, @alena?)

---

<div class="post-metadata">

**Author:** ![alena](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alena/32/50_2.png) [@alena](https://forums.suse.com/u/alena)\
**Post date:** [August 3, 2016, 4:36pm UTC](https://forums.suse.com/t/request-host-on-loadbalancer-doesnt-work-as-expected-might-i-be-doing-something-wrong/3453/6 "2016-08-03T16:36:18Z")

</div>

@vincent yes, SNI routing will be a part of LB refactor
