frontend fe_ssh bind *:222 ssl crt /etc/haproxy/certs/ssl.pem ca-file /etc/haproxy/certs/LabCA.pem verify required mode tcp log-format "%ci:%cp [%t] %ft %b/%s %Tw/%Tc/%Tt %B %ts %ac/%fc/%bc/%sc/%rc %sq/%bq dstName:%[var(sess.dstName)] dstIP:%[var(sess.dstIP)] user:%[ssl_c_s_dn(CN)]" tcp-request content do-resolve(sess.dstIP,internal,ipv4) ssl_fc_sni tcp-request content set-var(sess.dstName) ssl_fc_sni default_backend ssh-all