DTLS Load Balancing

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view

DTLS Load Balancing

Sékine Coulibaly
I've setup a simplisti UDP load balancing as follow :

stream {
  upstream dtls_udp_upstreams {
    hash $remote_addr:remote_port;

  server {
    listen 5684 udp;
    proxy_pass dtls_udp_upstreams;
    proxy_responses 1;

I notice that the balancing is correctly done and the response is received by the client. Unfortunately, the destination port on the response reaching the client is not the initial source port, and as a consequence, the DTLS frame is discarded and a new DTLS handshake is initiated. 

When proxying UDP packets through Nginx, is there a way for Nginx to preserve its initial source port for subsequent packets?

In my case using Transparent proxying is not possible because my hoster doesn't allow IP spoofing.

Thank you !

nginx mailing list
[hidden email]