# Graylog behind 2 reverse proxies

**URL:** <https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809>\
**Category:** Graylog Central (peer support)\
**Created:** [August 15, 2020, 12:22am UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809 "2020-08-15T00:22:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![btown1](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@btown1](https://community.graylog.org/u/btown1)\
**Post date:** [August 15, 2020, 12:22am UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/1 "2020-08-15T00:22:08Z")

</div>

My setup is a reverse proxy on our boundary that is pointing into our internal network and my graylog server.

I set up my graylog server running apache with following config to reverse proxy it locally, which works just fine with following setup:

> \<VirtualHost _:80\>  
> ServerName graylog.internal.domain  
> RewriteEngine On  
> RewriteCond %{HTTPS} !=on  
> RewriteRule ^/?(._) https://%{SERVER\_NAME}/$1 [R,L]  
>   
> \<VirtualHost \*:443\>  
> ServerName graylog.internal.domain  
> ProxyRequests On  
> SSLEngine on  
> SSLCertificateFile /etc/pki/tls/certs/graylog.pem  
> SSLCertificateKeyFile /etc/httpd/graylog.key  
> SSLCACertificateFile /etc/pki/tls/certs/ca.pem  
> \<Proxy \*\>  
> Order deny,allow  
> Allow from all  
>   
>   
> RequestHeader set X-Graylog-Server-URL “https ://graylog.internal.domain/”  
> ProxyPass http ://127.0.0.1:9000/  
> ProxyPassReverse http ://127.0.0.1:9000/

My outside proxy has the following config pointing at it:

> \<Location /graylog\>  
> ProxyPass https: [//graylog.internal.domain/](https://graylog.internal.domain/)  
> ProxyPassReverse https ://graylog.internal.domain/

When I click the link on the outside proxy all I get is just a static white page instead of the graylog login. Is there a subpath or something in graylog server.conf I should be using? I modified the trusted\_proxies setting but that didn’t seem to work.

---

<div class="post-metadata">

**Author:** ![btown1](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@btown1](https://community.graylog.org/u/btown1)\
**Post date:** [August 15, 2020, 12:42am UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/2 "2020-08-15T00:42:37Z")

</div>

If I turn off httpd on the graylog server itself and set it up to bind to $IP:9000 and set http\_external\_uri to the [https://graylog.internal.domain:9000/](https://graylog.internal.domain:9000/) address it still works (with cert config setup in server.conf as well)

But on the outside proxy, pointing it to ProxyPass [https://graylog.internal.domain:9000/](https://graylog.internal.domain:9000/) fails with:

> # Service Unavailable
> 
> The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later

---

<div class="post-metadata">

**Author:** ![btown1](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@btown1](https://community.graylog.org/u/btown1)\
**Post date:** [August 15, 2020, 8:33pm UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/3 "2020-08-15T20:33:07Z")

</div>

![graylog](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/7/7946e4aa917e2c4fcb14f8db76e2a48104f932fb.jpeg)

Above when I get a blank screen connecting to Graylog through the proxy.

---

<div class="post-metadata">

**Author:** ![btown1](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@btown1](https://community.graylog.org/u/btown1)\
**Post date:** [August 15, 2020, 9:38pm UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/4 "2020-08-15T21:38:12Z")

</div>

> Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> vendor.043dd426065882df527b.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> polyfill.96312c8d18c5b4ff37d5.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> builtins.96312c8d18c5b4ff37d5.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> plugin.org.graylog.plugins.threatintel.ThreatIntelPlugin.53e617da22c5598ebd0b.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> plugin.org.graylog.plugins.enterprise.EnterprisePlugin.6257bf162acbffe11658.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> plugin.org.graylog.plugins.collector.CollectorPlugin.b88363aeddd823827582.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> plugin.org.graylog.integrations.IntegrationsPlugin.de432cfc8976a7cb4e52.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> plugin.org.graylog.enterprise.integrations.EnterpriseIntegrationsPlugin.5044caa597d2747788c6.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> plugin.org.graylog.aws.AWSPlugin.16a8c0b2427d3a1e285c.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED  
> app.96312c8d18c5b4ff37d5.js:1 Failed to load resource: net::ERR\_NAME\_NOT\_RESOLVED

---

<div class="post-metadata">

**Author:** ![btown1](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@btown1](https://community.graylog.org/u/btown1)\
**Post date:** [August 17, 2020, 6:09pm UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/5 "2020-08-17T18:09:05Z")

</div>

I did see this in the config, but not sure how to translate it to Apache

server  
{  
listen 80 default\_server;  
listen [::]:80 default\_server ipv6only=on;  
server\_name [applications.example.org](http://applications.example.org);

```
location /graylog/
{
  proxy_set_header Host $http_host;
  proxy_set_header X-Forwarded-Host $host;
  proxy_set_header X-Forwarded-Server $host;
  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header X-Graylog-Server-URL http://$server_name/graylog/;
  rewrite ^/graylog/(.*)$ /$1 break;
  proxy_pass http://127.0.0.1:9000;
}

```

}

---

<div class="post-metadata">

**Author:** ![btown1](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@btown1](https://community.graylog.org/u/btown1)\
**Post date:** [August 18, 2020, 6:12pm UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/6 "2020-08-18T18:12:04Z")

</div>

Got it to work so for future people who google search this here is what I had to set up!

Graylog server.conf only has http\_bind set to 0.0.0.0:9000

Nginx config on graylog server:

> server  
> {  
> listen 443 ssl http2;  
> server\_name **external\_proxy\_hostname** ;  
> ssl\_certificate /etc/pki/tls/certs/graylog.pem;  
> ssl\_certificate\_key /etc/httpd/graylog.key;  
> location /graylog/  
> {  
> proxy\_set\_header Host $http\_host;  
> proxy\_set\_header X-Forwarded-Host $host;  
> proxy\_set\_header X-Forwarded-Server $host;  
> proxy\_set\_header X-Forwarded-For $proxy\_add\_x\_forwarded\_for;  
> proxy\_set\_header X-Graylog-Server-URL https://$server\_name/graylog/;  
> rewrite ^/graylog/(.\*)$ /$1 break;  
> proxy\_pass [http://127.0.0.1:9000](http://127.0.0.1:9000);  
> }  
> }

Make note that the server name is the external proxy, not the hostname of the graylog server

Apache config for external proxy:

> \<Location /graylog\>  
> ProxyPass https://$GRAYLOGIP/graylog/  
> ProxyPassReverse https://$GRAYLOGIP/graylog/

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 1, 2020, 6:12pm UTC](https://community.graylog.org/t/graylog-behind-2-reverse-proxies/16809/7 "2020-09-01T18:12:13Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
