Re: load balancing firewall traffic

From: Scott Smith <>
Date: Mon, 21 Apr 2008 23:05:44 -0700

Willy Tarreau wrote:
> No specific input. You should use "balance uri" though, in order to
> improve cache hit rate on your squids.

Hi Willy,

(Un)fortunately, the content that will be proxied is very short-lived and can not be cached, so my squids will be set to not cache anything at all. The purpose of this is to truly balance load across several firewalls ;)

The only problem I face currently is coming up with a way to transparently direct my HTTP traffic to the haproxy VIP. The use of an internal hostname--to which I referred initially--isn't going to work for me, so I have to either use fake DNS entries that resolve to my haproxy VIPs. This is not preferable, for obvious reasons.

