Re: HAProxy and proxy protocol support

Sam Varshavchik <[email protected]> Mon, 10 Jun 2024 08:17:24 -0400
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Pascal Véron writes:

> « HTML content follows
> »Hello,
>
> We installed 2 Courier servers in different datacenter behind a load balancer  
> provided by our hosting provider (OVHCloud).
> This load balancer are using HAproxy technology and proxy protocol.
>
> If we use load balancer without proxy protocol, all works well for clients.  
> SMTP, IMAP and POP connexions are fully fonctionnals. But there a problem we  
> can't solve. Courier server receive only load balancer's IP instead of real  
> origin IP (which is the one we want to have for logs, fail2ban, blacklists  
> check...)
>
> HAProxy provide some proxy protocol (v1, v2, v2-ssl...) to transmit origin  
> IP, but if we use proxy protocol on load balancer, it does not work
>
> > telnet [IP_LOAD_BALANCER] 587
> Trying [IP_LOAD_BALANCER]...
> Connected to [IP_LOAD_BALANCER].
> Escape character is '^]'.
> 220 [NAME_LOAD_BALANCER] ESMTP
> 502 ESMTP command error
> ...write in mail.log
>
> Jun 10 10:19:28  [NAME_LOAD_BALANCER]: error,relay=::ffff: 
> 10.110.97.193,port=29832,msg="502 ESMTP command error",cmd: PROXY TCP4  
> [REAL_IP_ORIGIN] [IP_LOAD_BALANCER] 56590 587
>
> Same with pop
>
> > telnet [IP_LOAD_BALANCER] 110
> Trying [IP_LOAD_BALANCER]...
> Connected to [IP_LOAD_BALANCER].
> Escape character is '^]'.
> +OK Hello there.
> -ERR Invalid command.
>
> So sadly as it stands we cannot use this system.
>
> So my question is : do you think this could be an interesting option to add  
> to Courier or not ?
>
> <URL:https://github.com/haproxy/haproxy/blob/master/doc/proxy- 
> protocol.txt>https://github.com/haproxy/haproxy/blob/master/doc/proxy- 
> protocol.txt
> <URL:https://www.haproxy.com/blog/use-the-proxy-protocol-to-preserve-a- 
> clients-ip-address>https://www.haproxy.com/blog/use-the-proxy-protocol-to- 
> preserve-a-clients-ip-address

At least version 1 looks simple enough to handle, however I don't use  
HAProxy myself, so this would be a hit or miss proposition, as far as  
testing goes.

_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZmbu1AAKCRCKYPgoojZS
4hNbAP4+wTxXj08iReufuboM6P5NT8B2IdbFmZqAHqud/I/etQD/b991+xa8rcud
g6zDRHyNKs+rFM9CgiVlchzsIQ82Qg0=
=AkIV
-----END PGP SIGNATURE-----