Using Proxy Protocol with NodeBalancers

When a NodeBalancer passes a request from a client to a backend node, information regarding the original client is not included by default. While this is fine for many environments, your applications may require original client information such as IP address or port. For these cases, NodeBalancers support Proxy Protocol for TCP connections so that you can pass client information to backend nodes.

What is Proxy Protocol

Proxy Protocol is an internet protocol for various high availability and load balancing solutions to carry information about a client directly to backend servers.

When selecting TCP as your NodeBalancer protocol, you can enable Proxy Protocol to add a header containing client information to backend nodes.

šŸ“˜

Backend Firewall & Application Rules

Backend nodes must also have Proxy Protocol enabled on supported applications to receive the client information header.

Additional configuration options may need to be enabled on the application or service to accommodate traffic between the node and the NodeBalancer, depending on your selected backend connectivity method (VPC, public IPv6, or legacy private IPv4).

Ensure your backend Linodes' firewall rules allow incoming traffic from the NodeBalancer based on your selected backend connectivity method:

  • Public IPv6: Retrieve your NodeBalancer's dedicated /96 IPv6 prefix using the Get a NodeBalancer's backend IPv6 prefix endpoint. Allow inbound traffic from this /96 prefix in your backend firewall.
  • VPC: Allow inbound traffic on your backend Linodes from the VPC Subnet IP range (e.g., 10.0.0.0/24) or the NodeBalancer's assigned VPC IP address.
  • Legacy Private IPv4: Allow inbound traffic from the NodeBalancer's private IPv4 address range (192.168.255.0/24).

Currently, there are two available versions of Proxy Protocol, v1 and v2:

  • v1: Proxy Protocol v1 adds a human readable string to all requests. Click on the tabs to see different examples:

    PROXY TCP4 198.51.100.25 203.0.113.10 56147 80
    PROXY TCP6 2001:db8::1 2600:3c22:1:20:0:3039::1 56147 80
    PROXY TCP4 198.51.100.25 10.0.0.2 56147 80
    PROXY TCP4 198.51.100.25 192.168.255.2 56147 80

    The syntax for this output is as follows:

      PROXY, PROTOCOL, CLIENT_IP, NODEBALANCER_IP, CLIENT ORIGIN PORT, NODEBALANCER PORT
  • v2: Proxy Protocol v2 adds a more efficient binary data header to all requests, similar to the following:

    \r\n\r\n\x00\r\nQUIT\n!\x11\x00\x0c\xach\x11\x05\xcf\xc0D8\xfe\x1e\x04\xd2

More information on v1 and v2 is available in The PROXY Protocol specification.

Configure Proxy Protocol

In order to make use of Proxy Protocol, it needs to be configured on the NodeBalancer as well as each backend node.

Configure the NodeBalancer

To enable Proxy Protocol for your NodeBalancer, follow the instructions below.

  1. Log in to Cloud Manager, click NodeBalancers in the left menu, and select the NodeBalancer you wish to edit. See Manage NodeBalancers.

  2. Navigate to the Configurations tab and open the port configuration you wish to edit.

  3. Ensure that the Protocol option is set to TCP, which makes the Proxy Protocol dropdown menu appear. Select the desired Proxy Protocol version.

  4. Click the Save button on the bottom of the page to Save your changes.

Configure the backend nodes

Once Proxy Protocol is configured for your NodeBalancer, ensure that it is also enabled for the receiving software on your backend nodes. You can find a list of compatible software in the Proxy protocol documentation. Here are links to guidance for enabling Proxy Protocol for common software:


Did this page help you?