Load balancing encrypted email traffic (IMAPS on port 993, POP3S on port 995, and SMTPS on port 465) using HAProxy requires two critical mechanisms: SSL offloading at the load balancer and the PROXY protocol to preserve the client's real public IP address in Dovecot and Postfix logs.
Architecture: Encrypted Client → HAProxy (SSL Termination &
send-proxy) → Dovecot / Postfix (Real IP Preserved)
1. HAProxy Configuration (haproxy.cfg)
frontend imaps_in
bind *:993 ssl crt /etc/ssl/certs/mail.pem
mode tcp
default_backend dovecot_imaps
backend dovecot_imaps
mode tcp
server mail1 10.0.0.1:10143 send-proxy check
2. Dovecot PROXY Protocol Support (/etc/dovecot/dovecot.conf)
Configure Dovecot to accept the PROXY protocol header to log the real client IP:
service imap-login {
inet_listener imap_haproxy {
port = 10143
haproxy = yes
}
}
haproxy_trusted_networks = 10.0.0.0/24
But dovecot installation? postfix? ... :(
ReplyDeleteI haven’t checked in here for a while since I thought pirate proxy was getting boring, but the last several posts are good quality so I guess I will add you back to my everyday bloglist.
ReplyDeleteAlterations Boutique offers professional suit alterations, dress alterations, and wedding dress alterations in London. Their expert tailors provide precision adjustments to ensure a perfect fit for every garment, whether it's a suit, dress, or bridal gown. With personalized service and years of experience, they are dedicated to delivering the highest quality alterations. For more details, visit Alterations Boutique. proxysite.guru
ReplyDelete