Split DNS issue? Can't connect to local reverse proxy at Site2 using same domain name as Site1. #2408
Unanswered
partytimeexcellent
asked this question in
Q&A
Replies: 1 comment 1 reply
-
|
Ok here's an update that should help track down the issue: In the main VPS Pangolin instance, if I change the resource targets at Site2 from FQDN to IP ( So the question is, why can VPS Pangolin find Site1 Pangolin at This must be a DNS issue (it's always DNS, lol), but I am lost on how to find or change anything related to this. Thanks for any pointers |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
My main Pangolin instance is on a VPS with public DNS records pointing to it, accessed via
pangolin.uniquedomain.comThere are two Sites at two different physical locations, and both use a local-only Pangolin instance as a reverse proxy.
Location one Pangolin instance is accessed at
https://proxy.uniquedomain.comand all traffic from the main VPS instance is sent to this URL. This works perfectly, and there are many resources all with names likeservice1.uniquedomain.comthat resolve perfectly fine with this setup.At location two, I have the exact same setup, except the URLs all have an additional subdomain (.site2),
https://proxy.site2.uniquedomain.com,service1.site2.uniquedomain.com, etc, (I have also triedproxy-site2.uniquedomain.com). Unfortunately the main Pangolin VPS instance is not properly connecting to this local Site2 Pangolin reverse proxy. All requests just time out. (and also cause RAM usage to spike). For resources that are protected by SSO Auth on the VPS instance, redirecting to the sign-in page works, but then after successful login, it goes back to timing out.The weird thing is, there doesn't seem to be a problem using
uniquedomain.comat both sites because I can create resources that skip the local Pangolin reverse proxy and point directly to the service, such asservice1-site2.uniquedomain.comwhile concurrently sending traffic to Site1 just fine. So I'm confused about what possible DNS issue might be happeningI have tried numerous combinations of entries into the "TLS Server Name" and "Custom Host Header" fields without luck. (Site1 works fine with no entries in these fields.). I tried this because I have a third site with a different domain name, and I needed to use TLS Server Name:
uniquedomain2.com, and Custom Host Header:proxy.uniquedomain2.comto get it working, although that was presenting a 502 error without them, not timing out.There is no issue with the Site2 Pangolin reverse proxy if I open local ports and change the public DNS to point directly to it instead of the VPS, everything behaves normally. Private resources also work perfectly fine at both Sites.
Trying to make sense of my limited knowledge in the Traefik logs:
302 error on "/" is often the first thing to come up when I try to access the URL. Followed by 504 or 499.
Sometimes I see 302 on
/?resource_session_request_param=pumreoqwbugyh7d.....after an auth login.So, I've exhausted my troubleshooting on this setup. Anyone have ideas why I can't connect to this Site2 Pangolin reverse proxy instance? Is there any type of logging that could show why It's timing out?
Thanks for any insights!
Beta Was this translation helpful? Give feedback.
All reactions