Hi,

    Greetings,
I am facing issue in HA for SFTP nodes with haproxy. I have 2 SFTP nodes and sending files through haproxy, It is always passing that to each node one by one.
But for ex:
when the second node is down. it is not passing files to only first node. instead, one time to first node and one time to second node. That means alternatively my second request is getting failures. how to fix this. please help me asap.


_*haproxy.cfg*_  (Also attached the cfg file)


OS - linux ubuntu







--
*Thanks*
*Vijay*
global
        log /dev/log    local0
        log /dev/log    local1 notice
        chroot /var/lib/haproxy
        stats socket /run/haproxy/admin.sock mode 660 level admin
        stats timeout 30s
        user haproxy
        group haproxy
        daemon

        # Default SSL material locations
        ca-base /etc/ssl/certs
        crt-base /etc/ssl/private

        # Default ciphers to use on SSL-enabled listening sockets.
        # For more information, see ciphers(1SSL). This list is from:
        #  https://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/
        ssl-default-bind-ciphers 
ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS
        ssl-default-bind-options no-sslv3

defaults
        log     global
        mode    http
        option  httplog
        option  dontlognull
        timeout connect 5000
        timeout client  50000
        timeout server  50000
        errorfile 400 /etc/haproxy/errors/400.http
        errorfile 403 /etc/haproxy/errors/403.http
        errorfile 408 /etc/haproxy/errors/408.http
        errorfile 500 /etc/haproxy/errors/500.http
        errorfile 502 /etc/haproxy/errors/502.http
        errorfile 503 /etc/haproxy/errors/503.http
        errorfile 504 /etc/haproxy/errors/504.http

listen sftp-server
        bind :2121
        mode tcp
        maxconn 2000
        #acl white_list src 8.8.8.8 8.8.8.9
        #tcp-request content accept if white_list
        #tcp-request content reject
        balance roundrobin
        option tcplog
        option tcp-check
        server ftp01 172.21.10.100:22
        server ftp02 172.21.10.101:22

Reply via email to