PageSourceSearch

https://www.ans.co.uk/docs/assets/js/58b8cc1e.96e456d2.js

js ans.co.uk collected 2026-10-02 17:24:41 UTC 11,991 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkans_co_uk_docs=globalThis.webpackChunkans_co_uk_docs||[]).push([[21782],{1633:(e,n,r)=>{r.r(n),r.d(n,{assets:()=>d,contentTitle:()=>i,default:()=>h,frontMatter:()=>a,metadata:()=>o,toc:()=>l});const o=JSON.parse('{"id":"network/load-balancers/faqs/index","title":"FAQs","description":"An FAQ for loadbalancers with ANS","source":"@site/docs/network/load-balancers/faqs/index.md","sourceDirName":"network/load-balancers/faqs","slug":"/network/load-balancers/faqs/","permalink":"/docs/network/load-balancers/faqs/","draft":false,"unlisted":false,"editUrl":"https://github.com/ans-group/ans.co.uk-docs/tree/main/docs/network/load-balancers/faqs/index.md","tags":[],"version":"current","sidebarPosition":6,"frontMatter":{"sidebar_position":6,"sidebar_label":"FAQs","title":"FAQs","description":"An FAQ for loadbalancers with ANS","keywords":["ans","loadbalancing","loadbalancer","faq"]},"sidebar":"documentationSidebar","previous":{"title":"Common changes","permalink":"/docs/network/load-balancers/common-changes/"},"next":{"title":"Policy","permalink":"/docs/network/policy/"}}');var t=r(74848),s=r(28453);const a={sidebar_position:6,sidebar_label:"FAQs",title:"FAQs",description:"An FAQ for loadbalancers with ANS",keywords:["ans","loadbalancing","loadbalancer","faq"]},i="FAQs",d={},l=[{value:"How do I replace an expired certificate?",id:"how-do-i-replace-an-expired-certificate",level:2},{value:"How do I drain traffic from a particular target server?",id:"how-do-i-drain-traffic-from-a-particular-target-server",level:2},{value:"Why is all my traffic now coming from one IP?",id:"why-is-all-my-traffic-now-coming-from-one-ip",level:2},{value:"I&#39;m getting a redirect loop when redirecting to HTTPS, how can I fix this?",id:"im-getting-a-redirect-loop-when-redirecting-to-https-how-can-i-fix-this",level:2},{value:"How do I setup SSL passthrough?",id:"how-do-i-setup-ssl-passthrough",level:2},{value:"What is the meaning behind the <code>SERVERID</code> cookie?",id:"what-is-the-meaning-behind-the-serverid-cookie",level:2}];function c(e){const n={a:"a",code:"code",h1:"h1",h2:"h2",header:"header",p:"p",pre:"pre",strong:"strong",...(0,s.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(n.header,{children:(0,t.jsx)(n.h1,{id:"faqs",children:"FAQs"})}),"\n",(0,t.jsx)(n.p,{children:"Here are some of the most frequently asked questions we get about our load balancers to help save you time."}),"\n",(0,t.jsx)(n.h2,{id:"how-do-i-replace-an-expired-certificate",children:"How do I replace an expired certificate?"}),"\n",(0,t.jsxs)(n.p,{children:["This is covered in our ",(0,t.jsx)(n.a,{href:"../common-changes/#replacing-an-expired-ssl-certificate",children:"common changes"})," page."]}),"\n",(0,t.jsx)(n.h2,{id:"how-do-i-drain-traffic-from-a-particular-target-server",children:"How do I drain traffic from a particular target server?"}),"\n",(0,t.jsxs)(n.p,{children:["This is covered in our ",(0,t.jsx)(n.a,{href:"../common-changes/#drain-traffic-from-a-particular-target-server",children:"common changes"})," page."]}),"\n",(0,t.jsxs)(n.p,{children:["This is covered in our ",(0,t.jsx)(n.a,{href:"../common-changes/#temporarily-remove-a-target-server-from-behind-the-load-balancer",children:"common changes"})," page."]}),"\n",(0,t.jsx)(n.h2,{id:"why-is-all-my-traffic-now-coming-from-one-ip",children:"Why is all my traffic now coming from one IP?"}),"\n",(0,t.jsx)(n.p,{children:"Once you've moved behind a load balancer, you may notice that some of your analytics on your backend servers, along with your logs appear to break. Where you used to see a breakdown of all the visitors to your site, you now just see one persistent visitor. The numbers won't have changed, but the IP address will have."}),"\n",(0,t.jsx)(n.p,{children:"This is down to the nature of the load balancer itself. Where visitors used to directly visit your server, they now visit the load balancer instead and it's the load balancer that makes requests to the backend server. As such, the only IP address you'll see in logs or analytics will likely be that of the load balancer."}),"\n",(0,t.jsxs)(n.p,{children:["There's an easy fix. Whereas logs and analytics will usually derive the visitor IP from the source of the request, they need to be directed to look at the standard ",(0,t.jsx)(n.code,{children:"X-Forwarded-For"})," header instead. This is injected by the load balancer automatically, so should already be present. If you have HTTPS passthrough enabled or are using TCP mode then you will need to enable the PROXY protocol on the edit target group screen for this to work. This also requires additional setup on your web / application servers."]}),"\n",(0,t.jsx)(n.p,{children:"How this is achieved will depend on what solution you're trying to work with. Here are a few examples:"}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"Apache:"})}),"\n",(0,t.jsxs)(n.p,{children:["Apache has an optional module called ",(0,t.jsx)(n.code,{children:"mod_rpaf"})," that handles the transition from source to ",(0,t.jsx)(n.code,{children:"X-Forwarded-For"}
1),", so with it set up you shouldn't really notice any difference from that point onward."]}),"\n",(0,t.jsx)(n.p,{children:"It's not installed by default, so install it like so:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"  yum install mod_rpaf\n"})}),"\n",(0,t.jsxs)(n.p,{children:["After that, edit ",(0,t.jsx)(n.code,{children:"/etc/httpd/conf.d/mod_rpaf.conf"})," and put the following content in:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-apacheconf",children:"\n  LoadModule rpaf_module modules/mod_rpaf-2.0.so\n\n  RPAFenable On\n  RPAFsethostname On\n  RPAFproxy_ips 1.1.1.1 2.2.2.2 127.0.0.1\n  RPAFheader X-Forwarded-For\n"})}),"\n",(0,t.jsxs)(n.p,{children:["Replace ",(0,t.jsx)(n.code,{children:"1.1.1.1"})," and ",(0,t.jsx)(n.code,{children:"2.2.2.2"})," with the IP address(es) your load balancer is sending traffic from and restart Apache to put it all live:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"  service httpd restart\n"})}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"NGINX:"})}),"\n",(0,t.jsxs)(n.p,{children:["The comparable module for NGINX is called ",(0,t.jsx)(n.code,{children:"ngx_http_realip_module"}),": ",(0,t.jsx)(n.a,{href:"http://nginx.org/en/docs/http/ngx_http_realip_module.html",children:"http://nginx.org/en/docs/http/ngx_http_realip_module.html"})]}),"\n",(0,t.jsxs)(n.p,{children:["If your install of NGINX was compiled with ",(0,t.jsx)(n.code,{children:"--with-http_realip_module"})," then you should be able to make use of it like so in your ",(0,t.jsx)(n.code,{children:"nginx.conf"}),":"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"  set_real_ip_from 1.1.1.1;\n  real_ip_header    X-Forwarded-For;\n"})}),"\n",(0,t.jsxs)(n.p,{children:["As mentioned for Apache, ",(0,t.jsx)(n.code,{children:"1.1.1.1"})," should be replaced with the IP address that's now sending all the traffic to your servers."]}),"\n",(0,t.jsx)(n.p,{children:"Then restart NGINX to put it live:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"  service nginx restart\n"})}),"\n",(0,t.jsx)(n.h2,{id:"im-getting-a-redirect-loop-when-redirecting-to-https-how-can-i-fix-this",children:"I'm getting a redirect loop when redirecting to HTTPS, how can I fix this?"}),"\n",(0,t.jsx)(n.p,{children:"In some configurations, performing a HTTP->HTTPS redirect from a server behind a load balancer may result in your website experiencing a redirect loop. As the HTTPS connection is terminated at the load balancer, the backend servers only see HTTP connections and continually try to redirect the client to a HTTPS URL."}),"\n",(0,t.jsxs)(n.p,{children:["Ideally you should perform your HTTP->HTTPS redirects directly on the load balancer using the option available in the Listener configuration section, however if this is not an acceptable solution, you can confirm if a client is using HTTPS connections to the load balancer by checking the ",(0,t.jsx)(n.code,{children:"X-Forwarded-Proto"})," header. This header will be present and contain the value ",(0,t.jsx)(n.code,{children:"https"})," when connections to the load balancer are occurring over HTTPS. You can check this header to perform conditional redirects to HTTPS on your backend servers, for example:"]}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"Apache:"})}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"RewriteCond %{HTTP:X-Forwarded-Proto} !https\nRewriteCond %{HTTPS} off\nRewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301,NE]\n"})}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"NGINX:"})}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:'if ($http_x_forwarded_proto = "http") {\n    return 301 https://$server_name$request_uri;\n}\n'})}),"\n",(0,t.jsx)(n.h2,{id:"how-do-i-setup-ssl-passthrough",children:"How do I setup SSL passthrough?"}),"\n",(0,t.jsx)(n.p,{children:"To setup SSL passthrough you should create a TCP listener with an IP binding on port 443. You can then point this to your target groups as you would normally."}),"\n",(0,t.jsxs)(n.h2,{id:"what-is-the-meaning-behind-the-serverid-cookie",children:["What is the meaning behind the ",(0,t.jsx)(n.code,{children:"SERVERID"})," cookie?"]}
1),"\n",(0,t.jsxs)(n.p,{children:["When you have sticky sessions enabled on your target group, the load balancer will insert a ",(0,t.jsx)(n.code,{children:"SERVERID"})," cookie into the response for the client's browser to send back in future requests. This will be used by the loadbalancer to ensure a session 'sticks' to the same backend server, removing the need for shared session storage on the backend."]}),"\n",(0,t.jsxs)(n.p,{children:["The format of the ",(0,t.jsx)(n.code,{children:"SERVERID"})," cookie follows the format:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"srv$INDEX_$TARGETGROUP_$IP\n"})}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"$INDEX"})," value starts at zero and is incremented for each of your target servers. As long as the number and order of target servers stays the same, this will remain consistent."]}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"$TARGETGROUP"})," value is a BLAKE2b hash of the target group name, with a digest size of 2. This will not change as long as your target group name stays the same. You can find out the value of ",(0,t.jsx)(n.code,{children:"$TARGETGROUP"})," ahead of time by passing your target group name through the BLAKE2b hashing algorithm. If you have Python3 available, this can be done as follows, replacing 'Foo Bar' with your value:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{children:"$ python3 -c \"import hashlib; print(hashlib.blake2b('Foo Bar'.encode('utf-8'), digest_size=2).hexdigest())\"\na54b\n"})}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"$IP"})," value is the last octet of the server's IP address, usually the internal (or RFC1918) address, but this does depend on your individual networking setup."]}),"\n",(0,t.jsxs)(n.p,{children:["For example: ",(0,t.jsx)(n.code,{children:"srv0_a54b_57"}),". This would be the first server in your 'Foo Bar' target group, and the IP address of that server would end in ",(0,t.jsx)(n.code,{children:".57"}),", (e.g. ",(0,t.jsx)(n.code,{children:"192.168.1.57"}),")."]})]})}function h(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,t.jsx)(n,{...e,children:(0,t.jsx)(c,{...e})}):c(e)}},28453:(e,n,r)=>{r.d(n,{R:()=>a,x:()=>i});var o=r(96540);const t={},s=o.createContext(t);function a(e){const n=o.useContext(s);return o.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function i(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:a(e.components),o.createElement(s.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.