Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure HAProxy by defining a client-facing frontend, one or more destination backend pools, a matching mode (HTTP or TCP), a balancing algorithm, and health checks. Add TLS deliberately on the client side, the backend side, or both. Validate the file and reload HAProxy using the procedure supported by your installed version and service manager.

Understand the HAProxy configuration model

The standard configuration file is commonly /etc/haproxy/haproxy.cfg, although packages and operating systems can use different paths. Most configurations contain these sections:

Section Purpose
global Process-wide settings such as logging, connection limits, user/group, and chroot behavior.
defaults Settings inherited by subsequent proxy sections, including mode and timeouts.
frontend The IP address and port clients connect to, plus request routing rules.
backend A pool of destination servers and the policy used to distribute traffic.
listen A combined frontend/backend section that can simplify a single service.

Separate frontends and backends are generally easier to maintain when several hostnames or application pools share one HAProxy instance.

Choose HTTP or TCP mode

Mode Use it when What HAProxy can do
http The service speaks HTTP and you need HTTP-aware routing. Inspect HTTP messages and route by metadata such as the Host header.
tcp The service is non-HTTP TCP, or you need stream proxying without HTTP inspection. Proxy TCP connections without HTTP-layer routing.

Keep the frontend and backend modes aligned. TCP mode is appropriate for services such as database connections; HTTP mode is required for rules that inspect HTTP requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Build a basic HTTP reverse proxy and load balancer

The following is an illustrative starting point. Replace the addresses, ports, health path, and limits with values appropriate for your system; the timeout and connection values are not universal defaults.

global
  log 127.0.0.1 local0
  maxconn 60000

defaults
  mode http
  timeout connect 5s
  timeout client  30s
  timeout server  30s

frontend public_http
  bind :80
  default_backend app_servers

backend app_servers
  balance roundrobin
  option httpchk GET /health
  server app1 192.0.2.10:8080 check
  server app2 192.0.2.11:8080 check

What each part does

  • bind :80 accepts client connections on port 80 on the local addresses selected by the operating system.
  • default_backend app_servers sends requests that have no more specific rule to the named pool.
  • balance roundrobin selects the documented round-robin policy.
  • option httpchk GET /health asks each HTTP server to expose a meaningful readiness endpoint.
  • check enables active checking on each server line.

Route multiple applications with ACLs

For several sites or services, keep one frontend and choose a backend with request conditions. A Host-header example is:

frontend public_http
  bind :80
  acl host_api hdr(host) -i api.example.com
  acl host_web hdr(host) -i www.example.com
  use_backend api_servers if host_api
  use_backend web_servers if host_web
  default_backend web_servers

backend api_servers
  balance leastconn
  server api1 192.0.2.20:8080 check
  server api2 192.0.2.21:8080 check

backend web_servers
  balance roundrobin
  server web1 192.0.2.30:8080 check
  server web2 192.0.2.31:8080 check

Use a dedicated default_backend so requests that match no ACL have an intentional destination rather than an accidental one.

Rank #2
Omada ER707-M2, Multi-Gigabit VPN Route
  • 【Flexible Port Configuration】1 2.5Gigabit WAN Port + 1 2.5Gigabit WAN/LAN Ports + 4 Gigabit WAN/LAN Port + 1 Gigabit SFP WAN/LAN Port + 1 USB 2.0 Port (Supports USB storage and LTE backup with LTE dongle) provide high-bandwidth aggregation connectivity.
  • 【High-Performace Network Capacity】Maximum number of concurrent sessions – 500,000. Maximum number of clients – 1000+.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【Highly Secure VPN】Supports up to 100× LAN-to-LAN IPsec, 66× OpenVPN, 60× L2TP, and 60× PPTP VPN connections.
  • 【5 Years Warranty】Backed by our 5-years warranty and free technical support from 6am to 6pm PST Monday to Fridays

Choose a balancing algorithm

The balance directive controls how HAProxy selects a server. Available documented choices include:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Algorithm Use as a decision guide
roundrobin Cycle through servers for an even distribution when servers and requests are broadly similar.
leastconn Prefer the server with the fewest active connections, which can suit long-lived or uneven-duration connections.
random Distribute selections randomly when that behavior fits the workload.
first Prefer earlier servers in the configured order, subject to capacity and availability.
hash Use a hash-based policy when repeatable selection or a form of affinity is required.

There is no universally best algorithm. Base the choice on connection duration, request distribution, server capacity, and whether the application requires persistence. The available documentation does not establish performance measurements for a particular workload.

Add health checks that reflect application readiness

Health checks keep failed servers out of rotation and allow recovered servers to return after successful checks. A check on a server line can test basic TCP reachability:

Rank #3
Sale
TP-Link ER7206, Multi-WAN Professional Wired Gigabit VPN Router
  • 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
  • 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
  • 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.
server app1 192.0.2.10:8080 check

For HTTP, check an endpoint that represents real readiness rather than merely an open port:

backend app_servers
  option httpchk GET /health
  server app1 192.0.2.10:8080 check
  server app2 192.0.2.11:8080 check
  • A TCP check confirms that a connection can be made.
  • An HTTP check can exercise an endpoint and evaluate the response status or content according to the health-check settings you configure.
  • HAProxy removes a server after the configured failure threshold and restores it after the configured success threshold.
  • Choose a health endpoint that fails when the application cannot safely serve user traffic, not only when the process is listening.

Configure HTTPS at the edge

To terminate client TLS at HAProxy, attach a certificate bundle to a TLS bind:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
frontend public_https
  bind :443 ssl crt /path/to/site.pem
  default_backend app_servers

You can keep a separate port-80 frontend that redirects HTTP clients to HTTPS. The certificate path and bundle format must match your installation and certificate-management process.

Encrypt and verify HAProxy-to-backend traffic

Client-side TLS termination and upstream TLS are separate decisions. To make HAProxy connect to an HTTPS backend and validate its certificate, configure the server line with TLS verification and a trusted CA:

backend secure_app_servers
  server app1 app1.internal.example:8443 ssl verify required ca-file /path/to/ca.pem check

verify required checks the upstream certificate against the configured trust root. verify none disables that trust check and may be useful for narrowly controlled self-signed deployments, but it removes an important protection and should not be the routine production choice where a suitable CA can be configured.

Backend SNI considerations

HAProxy 3.3 and newer, along with the specifically documented newer product editions, set backend SNI from the Host header automatically. Confirm your installed version before relying on that behavior. Use explicit SNI settings, or disable automatic behavior, when your backend naming and certificate design require it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Cudy Gigabit Multi-WAN Router, OpenWRT, Load Balance, 5X GbE, R700
  • Multi-WAN Business Continuity: Connect up to 5 ISPs with automatic failover and load balancing — if one connection drops, traffic instantly reroutes to keep your business, remote office, or home lab online
  • OpenWRT-Ready Enterprise Control: Full OpenWRT support unlocks VLAN segmentation, advanced firewall rules, custom QoS policies, and community-developed packages for professional-grade network management
  • Complete VPN Gateway Suite: WireGuard, OpenVPN, IPsec, PPTP, and L2TP server and client built in; create site-to-site tunnels, host remote access, or route specific VLANs through encrypted VPN connections
  • Professional Security Stack: SPI firewall, DoS attack prevention, IP/MAC binding, domain filtering, and DMZ hosting protect your network perimeter while keeping critical services accessible
  • Flexible Deployment & Monitoring: Web GUI or Cudy App cloud management with TR-069 support; built-in diagnostic tools (Ping, Traceroute, NSLookup, system logs) for rapid troubleshooting anytime
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Validate, stage, and reload safely

  1. Check the installed HAProxy version and identify the configuration path and service manager used by your package.
  2. Save a known-good configuration and edit a staged copy.
  3. Validate the staged file with the HAProxy executable and configuration-path option supplied by your local package or service documentation.
  4. Apply the file with the service manager’s supported reload operation; the exact command is platform- and package-specific.
  5. Inspect HAProxy and application logs, backend health state, request routing, and TLS verification after the reload.
  6. Temporarily stop or isolate one backend and confirm that health checks remove it from rotation, then verify that it returns after recovery.

The documented no-impact master-worker reload behavior applies to HAProxy 3.1 and newer and named newer product editions. Earlier releases may drop connections during reloads, so confirm the behavior of your installed version before changing production configuration.

Troubleshoot common configuration failures

HAProxy will not start or reload

  • Run the version-appropriate configuration validation command and read the reported file and line number.
  • Check section names, indentation, certificate paths, address/port syntax, and duplicate server names.
  • Confirm that the bind address and port are available and that the HAProxy process has permission to read certificate and CA files.

All servers are marked down

  • Test reachability from the HAProxy host to each address and port.
  • Verify that the health-check path, protocol, expected status, and any Host/SNI requirements match the application.
  • Check firewall rules and whether the service is listening on the address HAProxy uses.

Traffic reaches the wrong pool

  • Inspect Host-header ACL spelling and case-insensitive matching.
  • Ensure use_backend rules appear before the intended fallback and that a deliberate default_backend exists.
  • Confirm that the frontend is running in HTTP mode; TCP mode cannot inspect HTTP headers.

Upstream HTTPS fails

  • Verify the CA file contains the issuing trust root and that the backend certificate name matches the name used for verification.
  • Check whether the backend requires SNI and whether your HAProxy version supplies it automatically or needs explicit configuration.
  • Do not switch to verify none merely to hide a trust or naming error without assessing the security impact.

Version and deployment cautions

HAProxy community, Enterprise, and ALOHA editions can differ in paths, controls, supported features, and operational procedures. Directives outside this minimal proxy/load-balancer path should be checked against the manual for the exact release and edition you run. The examples assume an HTTP application pool; adapt the mode, checks, TLS settings, and timeouts to your actual protocol and failure model.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.