# I am trying to proxy a grpc service while allowing passthrough mTLS

**URL:** <https://community.traefik.io/t/i-am-trying-to-proxy-a-grpc-service-while-allowing-passthrough-mtls/25146>\
**Category:** Traefik v2\
**Tags:** tcp, docker\
**Created:** [November 13, 2024, 11:40am UTC](https://community.traefik.io/t/i-am-trying-to-proxy-a-grpc-service-while-allowing-passthrough-mtls/25146 "2024-11-13T11:40:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SammyOina](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/sammyoina/32/9552_2.png) [@SammyOina](https://community.traefik.io/u/SammyOina)\
**Post date:** [November 13, 2024, 11:40am UTC](https://community.traefik.io/t/i-am-trying-to-proxy-a-grpc-service-while-allowing-passthrough-mtls/25146/1 "2024-11-13T11:40:51Z")

</div>

I want to proxy a service using traefik. The client and server connect over gRPC using mutual TLS. I want traefik to pass the certificates from the client and server without terminating tls. Would appreciate any help

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [November 13, 2024, 7:01pm UTC](https://community.traefik.io/t/i-am-trying-to-proxy-a-grpc-service-while-allowing-passthrough-mtls/25146/2 "2024-11-13T19:01:53Z")

</div>

If Traefik has no access to the TLS cert, you can only use a separate `entrypoint` (port) and a TCP router with rule `HostSNI(`*`)`.

Do not activate any TLS on the `entrypoint` or `router`, or Traefik will create a default TLS cert, which your client will not trust.

---

<div class="post-metadata">

**Author:** ![SammyOina](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/sammyoina/32/9552_2.png) [@SammyOina](https://community.traefik.io/u/SammyOina)\
**Post date:** [November 18, 2024, 1:39pm UTC](https://community.traefik.io/t/i-am-trying-to-proxy-a-grpc-service-while-allowing-passthrough-mtls/25146/3 "2024-11-18T13:39:04Z")

</div>

this worked, the basic config is as follows:

```auto
[entryPoints.tcp]
    address = ":8855"

[tcp]
  [tcp.routers]
    [tcp.routers.all-hosts-router]
      entryPoints = ["tcp"]
      rule = "HostSNI(`*`)"
      service = "backend-service"

  [tcp.services]
    [tcp.services.backend-service]
      [tcp.services.backend-service.loadBalancer]
        [[tcp.services.backend-service.loadBalancer.servers]]
          address = "backends:7011"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [November 21, 2024, 1:39pm UTC](https://community.traefik.io/t/i-am-trying-to-proxy-a-grpc-service-while-allowing-passthrough-mtls/25146/4 "2024-11-21T13:39:08Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
