# How to forward requests to a local IP

**URL:** <https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795>\
**Category:** Traefik v2\
**Tags:** docker, file, cli\
**Created:** [June 17, 2022, 8:22am UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795 "2022-06-17T08:22:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![floatingpurr](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/floatingpurr/32/1888_2.png) [@floatingpurr](https://community.traefik.io/u/floatingpurr)\
**Post date:** [June 17, 2022, 8:22am UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/1 "2022-06-17T08:22:43Z")

</div>

Hi, I use Traefik 2.x for my docker container. Now, I need also to forward requests coming to [foo.example.org](http://foo.example.org) to another private host ([http://192.168.0.50:8080](http://192.168.0.50:8080)) that is reachable from the machine hosting both Traefik and Docker.

Usually I do this kind of things spinning up a dedicated Nginx container this way:

```yaml
version: '3'

services:
   nginx:
        image: nginx
        restart: unless-stopped
        volumes:
              - ./log/:/log/
              - ./nginx.conf:/etc/nginx/conf.d/default.conf
        expose:
              - 80
        labels:
                traefik.enable: true
                traefik.http.routers.myService.rule: Host(`foo.example.org/`)
                traefik.http.routers.myService.entrypoints: websecure
                traefik.http.routers.myService.tls.certresolver: tlsleresolver        
        networks:
                - proxy

networks:
    proxy:
        external: true

```

with this config

> **nginx.conf**
>
> ```auto
> upstream myService {
> server 192.168.0.50:8080;
> }
> 
> server {
> listen 80;
> server_name foo.example.org;
> access_log /log/access.log main;
> location / {
> proxy_pass http://myService;
> proxy_http_version 1.1;
> proxy_set_header Upgrade $http_upgrade;
> proxy_set_header Connection "upgrade";
> proxy_set_header Host $http_host;
> 
> proxy_set_header X-Real-IP $remote_addr;
> proxy_set_header X-Forward-For $proxy_add_x_forwarded_for;
> proxy_set_header X-Forward-Proto http;
> proxy_set_header X-Nginx-Proxy true;
> 
> proxy_redirect off;
> 
> }
> }
> 
> ```

I'm wondering if I can get rid of Nginx and ask Traefik to do such a job. Here is my new config:

```yaml
version: '3.7'

services:
  traefik:
    image: traefik:v2.5
    container_name: traefik
    security_opt:
      - no-new-privileges:true
    restart: always
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - ./letsencrypt:/letsencrypt
      - ./.usersfile:/.usersfile
    ports:
      - 80:80
      - 443:443
    command:
      - --api.dashboard=true
      - --log.level=INFO
      - --providers.docker=true
      - --providers.docker.exposedbydefault=false
      - --providers.docker.network=proxy
      - --entrypoints.webinsecure.address=:80
      - --entrypoints.webinsecure.http.redirections.entrypoint.to=websecure
      - --entrypoints.webinsecure.http.redirections.entrypoint.scheme=https
      - --entrypoints.websecure.address=:443

      # TLS certificatesresolvers w/ Let's encrypt
      - --certificatesresolvers.tlsleresolver.acme.tlschallenge=true
      - --certificatesresolvers.tlsleresolver.acme.email=myemail@example.org
      - --certificatesresolvers.tlsleresolver.acme.storage=/letsencrypt/acme.json

    networks:
      - proxy

    labels:
      traefik.enable: true

      # Dashboard
      traefik.http.routers.traefik.rule: Host(`traefik.example.org`)
      traefik.http.routers.traefik.service: api@internal
      traefik.http.routers.traefik.entrypoints: websecure
      traefik.http.routers.traefik.tls.certresolver: tlsleresolver
      traefik.http.routers.traefik.middlewares: traefik-auth
      traefik.http.middlewares.traefik-auth.basicauth.usersfile: /.usersfile

      # Mimicking Nginx
      traefik.http.routers.foo.rule: Host(`foo.example.org`)
      traefik.http.routers.foo.service: foo
      traefik.http.routers.foo.entrypoints: websecure
      traefik.http.routers.foo.tls.certresolver: tlsleresolver
      traefik.http.services.foo.loadbalancer.server.url: http://192.168.0.50:8080

networks:
  proxy:
    external: true

```

But I got "too many redirects". How can I do it?

---

<div class="post-metadata">

**Author:** ![moutoum](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/moutoum/32/5325_2.png) [@moutoum](https://community.traefik.io/u/moutoum)\
**Post date:** [June 17, 2022, 9:28am UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/2 "2022-06-17T09:28:11Z")

</div>

Hi @floatingpurr,  
Thanks for your interest in Traefik.

The "too many redirects" error comes from a loop that occurs in your traefik container.  
When using traefik labels for dynamic configuration, the server url is not configurable and always points to the container ip. The label `traefik.http.services.foo.loadbalancer.server.url` with the value `http://192.168.0.8080` is just ignored.

For you use case, I suggest you to use the file provider for the dynamic configuration.  
To do so, you have to:

- enable the [file provider](https://doc.traefik.io/traefik/providers/file/) in the traefik command:

```auto
command:
  --providers.file.filename=/path/to/dynamic.yml
volumes:
  - ./config.yml:/path/to/dynamic.yml

```

- create the dynamic config file (`./config.yml`):

```auto
http:
  routers:
    foo:
      rule: Host(`match.example.com`)
      service: foo

  services:
    foo:
      loadBalancer:
        servers:
          - url: http://host.docker.internal:8081

```

---

<div class="post-metadata">

**Author:** ![floatingpurr](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/floatingpurr/32/1888_2.png) [@floatingpurr](https://community.traefik.io/u/floatingpurr)\
**Post date:** [June 17, 2022, 1:58pm UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/3 "2022-06-17T13:58:39Z")

</div>

Thank you @moutoum, adding the file provider fixed my problem. Thanx for describing the machinery behind that!

---

<div class="post-metadata">

**Author:** ![LubricantJam](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/lubricantjam/32/5485_2.png) [@LubricantJam](https://community.traefik.io/u/LubricantJam)\
**Post date:** [June 18, 2022, 11:27pm UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/4 "2022-06-18T23:27:32Z")

</div>

Hi @moutoum!

I am trying to implement this into my Jellyfin instance, as Jellyfin only allows you to send a password reset if coming from a local connection. I am trying to utilise this config in my dynamic config. Here's the nginx equivalent of what i'm trying to achieve.

> **[Password Resets outside local network](https://wiki.jfa-go.com/docs/password-resets/)**
>
> Password resets outside local network # If you have Jellyfin set up to recognize connections from the LAN network, it will complain when a user tries to do a password reset remotely:
> If you’re using a reverse proxy, Jellyfin knows the real IP of a...

This is what I've got so far but it doesn't seem to like me.

```auto
http:
  ## ROUTERS ##
  routers:
    forgot:
      entryPoints:
        - https
      rule: 'Host(`<redacted>`) && Path(`/Users/ForgotPassword`)'
      service: forgot
      middlewares:
      - passwordReset
    forgotPin:
      entryPoints:
        - https
      rule: 'Host(`<redacted>`) && Path(`/Users/ForgotPassword/Pin`)'
      service: forgotPin
      middlewares:
      - passwordReset

  ## SERVICES ##
  services:
    forgot:
      loadBalancer:
        servers:
          - url: http://jellyfin:8096/Users/ForgotPassword
    forgotPin:
      loadBalancer:
        servers:
          - url: http://jellyfin:8096/Users/ForgotPassword/Pin

  ## MIDDLEWARES ##
  middlewares:
    # Jellyfin Header
    passwordReset:
      headers:
        customRequestHeaders:
          X-Forwarded-For: 127.0.0.1

```

I appreciate any and all help!

---

<div class="post-metadata">

**Author:** ![moutoum](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/moutoum/32/5325_2.png) [@moutoum](https://community.traefik.io/u/moutoum)\
**Post date:** [June 20, 2022, 9:07am UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/5 "2022-06-20T09:07:33Z")

</div>

Hi @LubricantJam,  
Thanks for your interest in Traefik.

Your issue does not seem related to the previous content. Could you please open a new issue so it could help other users searching for the same issue later?

Thanks,  
Maxence

---

<div class="post-metadata">

**Author:** ![LubricantJam](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/lubricantjam/32/5485_2.png) [@LubricantJam](https://community.traefik.io/u/LubricantJam)\
**Post date:** [June 20, 2022, 10:21am UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/6 "2022-06-20T10:21:42Z")

</div>

No worries, I’ve moved it to [Translating NGINX to Traefik Rules](https://community.traefik.io/t/translating-nginx-to-traefik-rules/14817), thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [June 23, 2022, 10:22am UTC](https://community.traefik.io/t/how-to-forward-requests-to-a-local-ip/14795/7 "2022-06-23T10:22:33Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
