diff --git a/Ansible/roles/router/files/haproxy.cfg b/Ansible/roles/router/files/haproxy.cfg index 1368fd4bf96c85b22923eb9f9c0622854eb46585..34e85fec2ccc3a6527338a126e2de970adea7699 100644 --- a/Ansible/roles/router/files/haproxy.cfg +++ b/Ansible/roles/router/files/haproxy.cfg @@ -27,6 +27,16 @@ frontend http acl kodi hdr(host) -i kodi.shore.co.il acl kodi hdr(host) -i library.shore.co.il acl kodi hdr(host) -i transmission.shore.co.il + acl lam hdr(host) -i lam.shore.co.il + acl auth hdr(host) -i auth.shore.co.il + acl private_ip src 127.0.0.1/8 + acl private_ip src 10.0.0.0/8 + acl private_ip src 192.168.0.0/16 + acl private_ip src 172.16.0.0/12 + acl shore_ip src 62.219.131.121 + acl shore_ip src 163.172.74.36 + http-request deny if lam !private_ip + http-request deny if auth !shore_ip !private_ip use_backend kodi_http if kodi default_backend host01_http @@ -35,11 +45,22 @@ frontend https mode tcp option tcplog tcp-request inspect-delay 5s - tcp-request content accept if { req_ssl_hello_type 1 } acl kodi req_ssl_sni -i jellyfin.shore.co.il acl kodi req_ssl_sni -i kodi.shore.co.il acl kodi req_ssl_sni -i library.shore.co.il acl kodi req_ssl_sni -i transmission.shore.co.il + acl lam req_ssl_sni -i lam.shore.co.il + acl auth req_ssl_sni -i auth.shore.co.il + acl private_ip src 127.0.0.1/8 + acl private_ip src 10.0.0.0/8 + acl private_ip src 192.168.0.0/16 + acl private_ip src 172.16.0.0/12 + acl private_ip src 62.219.131.121 + acl shore_ip src 62.219.131.121 + acl shore_ip src 163.172.74.36 + tcp-request content reject if lam !private_ip + tcp-request content reject if auth !shore_ip !private_ip + tcp-request content accept if { req_ssl_hello_type 1 } use_backend kodi_https if kodi default_backend host01_https