DVLS with HAProxy

avatar

Hi

I'm proxying DVLS through HA Proxy, as I only have one certificate and IP.
I stumbled on that a previous release note said that it now supported reverse proxy.
My DVLS server is also running "fine" through HAProxy, but:
Especially from my iOS, I have to login 2-3 times. Often to receive a "not connected" but when refreshing the content comes to light.
I also ocationally experience the same ith RDM om Windows so:

I'm just wondering if this is because of the HAProxy, and if you have any gotchas or knowlage about what for sure needs to be set or disabled/no set?

As I'm no expert en HAProxy I have just setup 1 backend and then one frontend connected to the backend, everything with default values.

DVLS: 2022.2.5.0
RDM on iOS: 2022.2.0
RDM on Windows: Since RDM is good to save the creds, its been a while since I actually saw this, so not sure if this is relevant.

HAProxy running on pfSense v.: 2.6.0-RELEASE with HAProxy package 0.61_7 which includes HAProxy version 18-1.8.30

Regards Lars

Remote Desktop Manager connected with Devolutions Server running newest versions.

------------------------Signature------------------------

Sorry if any of above sounds harsh or provoking, it is NOT meant as such, but I have Asperger's and don't always know.
My intentions is always to be friendly.

-------------------------------------------------------------

All Comments (4)

avatar

Hello Lars,

For the release note regarding reverse proxy, it was for SSL stripping, meaning https was used to connect to the reverse proxy, but it was redirecting to the Devolutions Server with http after. Is this your case, or do you keep the certificate (https/https)? I assume it is the latter since you have the default values.

Make sure the Access URI configured in the DLVS and in RDM is pointing to the reverse proxy (#2): https://kb.devolutions.net/kb_dvls_accessuri.html

You can refer to this documentation for the pre-requisites for Load Balancing / Reverse Proxy: https://kb.devolutions.net/kb_dvls_deploy_high_availability_load_balanced_env.html

Do you have any issues connecting directly on the website, or only in RDM?

Best regards,

Richard Boisvert

avatar

Hi

Thank you for great information! - Yes I keep the certificate, and I have now added the x-forwarded-for.

My iOS RDM still needs 2 logins, but that is still better than before :)

Would it be better to do HTTPS/HTTP ?

/Lars M

Remote Desktop Manager connected with Devolutions Server running newest versions.

------------------------Signature------------------------

Sorry if any of above sounds harsh or provoking, it is NOT meant as such, but I have Asperger's and don't always know.
My intentions is always to be friendly.

-------------------------------------------------------------

avatar

Hello Lars,

Glad it is better now! Stripping the certificate can be faster by small margin, but it is not necessary at all.

For your iOS device, if you authenticate on the website directly, do you have to do it once or twice?

Best regards,

Richard Boisvert

avatar

I tried both Safari and my main browser Edge, and only 1 login needed.

I the tried deleting my data source and add it anew. Upon adding the data source again, I only needed to login 1 time.
So maybe it just needed to be readded. I will try and open it tomorrow again and see if it still only needs 1 login or 2 again.

I'll keep you updated.

/Lars

Remote Desktop Manager connected with Devolutions Server running newest versions.

------------------------Signature------------------------

Sorry if any of above sounds harsh or provoking, it is NOT meant as such, but I have Asperger's and don't always know.
My intentions is always to be friendly.

-------------------------------------------------------------