Re: [PATCH 0/7] Coccinelle

2021-09-17 Thread Willy Tarreau
Hi Tim, On Wed, Sep 15, 2021 at 01:58:42PM +0200, Tim Duesterhus wrote: > Willy, > > not sure about the "DOC" tag for the coccinelle patches and the placement > within the directory structure. Feel free to adjust. Good idea. I even remember that I was about to store some of my few coccinelle pat

Disabling HTTP/1.1 pipelining

2021-09-17 Thread Stefan Behte
Hi everyone, surely many on this list have heard about the meris botnet (https://krebsonsecurity.com/2021/09/krebsonsecurity-hit-by-huge-new-iot-botnet-meris/) which uses HTTP/1.1 pipelining for layer 7 attacks. As far as I can see, it's not possible to disallow HTTP pipelining in haproxy, so t

haproxy and CARP - binding a frontend to a specific IP on the backup-server

2021-09-17 Thread rainer
Hi, I run two FreeBSD 12.2 servers with haproxy 2.0.22 in a CARP setup. The frontend-interfaces have multiple IPs and I need to have this statement in at least one backend service: source 192.168.185.29 This is because the target-service has some whitelisting for this specific address.