# SSL enabled ports behind the load balancer

**URL:** <https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730>\
**Category:** Rancher 1.x\
**Created:** [October 20, 2015, 6:53pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730 "2015-10-20T18:53:38Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![fnord](https://avatars.discourse-cdn.com/v4/letter/f/97f17d/32.png) [@fnord](https://forums.suse.com/u/fnord)\
**Post date:** [October 20, 2015, 6:53pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/1 "2015-10-20T18:53:38Z")

</div>

I had to go into the haproxy config on an LB I’d created and manually set the backends to be ssl enabled. I also turned ssl-verify to none in the global section.

Am I missing something on the web interface that would let me configure a backend as ssl?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [October 20, 2015, 7:54pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/2 "2015-10-20T19:54:31Z")

</div>

The current options are:

- SSL passthrough, using a TCP listener instead of HTTP.

- SSL termination on the balancer.

We do not currently have a way to do termination + re-encryption (`request --ssl--> balancer --different-ssl--> container`). I know that’s an option that things like ELB have, but the communication from the balancer to the container is already running over an encrypted IPSec tunnel.

As I said in IRC, what you might actually need is just setting the target port to 80. If the target port is blank it defaults to the same as the source port, which if your server is also listening on 443 will send unencrypted requests to the encrypted port.

---

<div class="post-metadata">

**Author:** ![fnord](https://avatars.discourse-cdn.com/v4/letter/f/97f17d/32.png) [@fnord](https://forums.suse.com/u/fnord)\
**Post date:** [October 20, 2015, 8:06pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/3 "2015-10-20T20:06:06Z")

</div>

Thanks for the information

---

<div class="post-metadata">

**Author:** ![ammmze](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/ammmze/32/406_2.png) [@ammmze](https://forums.suse.com/u/ammmze)\
**Post date:** [October 24, 2015, 12:08am UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/4 "2015-10-24T00:08:07Z")

</div>

Are there plans to add this functionality?

I am working on using a suite of products from [WSO2](http://wso2.com/), which require even when fronted by an SSL terminating load balancer, to have the traffic hitting the product be coming in through SSL. I have attempted to to route it to the HTTP port (9763), but it always tries to redirect back to the SSL port (which then puts us in a redirect loop). For some parts of it, it would probably be okay to just do SSL pass through, but other parts do require session stickiness, which cannot be done with SSL pass through.

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [October 26, 2015, 6:30pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/5 "2015-10-26T18:30:12Z")

</div>

While we can’t commit to a date, we do review the list of feature requests frequently in GitHub. If you could create a request in GitHub, that’d be great.

---

<div class="post-metadata">

**Author:** ![ammmze](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/ammmze/32/406_2.png) [@ammmze](https://forums.suse.com/u/ammmze)\
**Post date:** [October 26, 2015, 6:58pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/6 "2015-10-26T18:58:01Z")

</div>

Done 🙂 Issue [#2448](https://github.com/rancher/rancher/issues/2448).

Thank you for your support!

---

<div class="post-metadata">

**Author:** ![alex88](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alex88/32/105_2.png) [@alex88](https://forums.suse.com/u/alex88)\
**Post date:** [November 10, 2015, 12:35am UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/7 "2015-11-10T00:35:19Z")

</div>

Is there a way to make the container has been ssl terminated?  
So for example I can enable http to https redirection at container level

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [November 17, 2015, 7:52pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/8 "2015-11-17T19:52:04Z")

</div>

@alex88 I don’t believe there is a way at this time. I believe #2448 is the enhancement request for what you are asking for.

---

<div class="post-metadata">

**Author:** ![alex88](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alex88/32/105_2.png) [@alex88](https://forums.suse.com/u/alex88)\
**Post date:** [November 17, 2015, 9:33pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/9 "2015-11-17T21:33:11Z")

</div>

To me that seems to have SSL on LB -\> container connection. My idea was to either add an header to the container requests from the LB that states the request was SSL terminated on the LB side

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [November 17, 2015, 10:50pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/10 "2015-11-17T22:50:24Z")

</div>

@alex88 SSL terminated HTTP requests have 2 headers added:

`X-Forwarded-For: <ip>` tells you the IP address that made the original request (since the request the target service sees will be from the load balancer’s IP)

`X-Forwarded-Proto: https` tells you that the request was originally SSL.

---

<div class="post-metadata">

**Author:** ![alex88](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alex88/32/105_2.png) [@alex88](https://forums.suse.com/u/alex88)\
**Post date:** [November 17, 2015, 11:04pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/11 "2015-11-17T23:04:04Z")

</div>

Oh awesome! The X-Forwarded-Proto was what I needed! Thanks!

---

<div class="post-metadata">

**Author:** ![juandavidgc](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@juandavidgc](https://forums.suse.com/u/juandavidgc)\
**Post date:** [May 31, 2016, 11:51pm UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/12 "2016-05-31T23:51:57Z")

</div>

Hi ammmze!

I’m working with WSO2 API Manager in Rancher, and I have the same problem. I’ve added a Rancher Load Balancer as the frontend, but I don’t know if you resolve the communication between the load balancer and the API Manager, because it has HTTPS exposed. How do you solve that? thanks!

---

<div class="post-metadata">

**Author:** ![ammmze](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/ammmze/32/406_2.png) [@ammmze](https://forums.suse.com/u/ammmze)\
**Post date:** [June 1, 2016, 12:17am UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/13 "2016-06-01T00:17:35Z")

</div>

We have an F5 load balancer and we ended up re-encrypting the traffic there. We also haven’t gotten enough buy in from everybody to use rancher, so we currently are just using different docker-compose files on our various hosts.

---

<div class="post-metadata">

**Author:** ![juandavidgc](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@juandavidgc](https://forums.suse.com/u/juandavidgc)\
**Post date:** [June 1, 2016, 12:47am UTC](https://forums.suse.com/t/ssl-enabled-ports-behind-the-load-balancer/730/14 "2016-06-01T00:47:42Z")

</div>

Ok ammmze, thanks a lot!
