<div dir="ltr">Ok ... after some more work I have it as follow and working. I created the certificates mentioned below as well :<br><br>upstream ucp_cluster {  <br>    server <a href="http://10.12.64.218:444">10.12.64.218:444</a>;<br>    server <a href="http://10.12.64.219:444">10.12.64.219:444</a>;<br>    server <a href="http://10.12.64.222:444">10.12.64.222:444</a>;<br>}<br><br>server {  <br>    listen 444 ssl;<br>    server_name docker-poc.<a href="http://domain.com" target="_blank">domain.com</a>;<br><br>    ssl on;<br>    ssl_certificate /etc/nginx/ssl/docker-poc.domain.com.crt;<br>    ssl_certificate_key /etc/nginx/ssl/docker-poc.domain.com.key;<br><br>    ssl_session_timeout 5m;<br><br>    ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;<br>    <br>    ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256";<br>    ssl_prefer_server_ciphers on;<br><br>    location / {<br>        proxy_set_header X-Real-IP $remote_addr;<br>        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header Host $http_host;<br>        proxy_set_header X-NginX-Proxy true;<br><br>        proxy_pass <a href="https://dtr_cluster/">https://dtr_cluster/</a>;<br>        proxy_redirect off;<br>    }<br>}<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Nov 15, 2016 at 4:43 PM, Yuriy Medvedev <span dir="ltr"><<a href="mailto:medvedev.yp@gmail.com" target="_blank">medvedev.yp@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Use <span style="font-size:12.8px">listen 443 ssl;</span> </div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><div class="gmail_quote">2016-11-15 17:34 GMT+03:00 Shaun Glass <span dir="ltr"><<a href="mailto:shaunglass@gmail.com" target="_blank">shaunglass@gmail.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Mmmm ... I gather that would be at the Docker Nodes. Just want nginx that when receiving a connection just connects to either of the 3.<br></div><div class="gmail_extra"><br><div class="gmail_quote"><div><div class="m_-4597194141808911213h5">On Tue, Nov 15, 2016 at 4:16 PM, Yuriy Medvedev <span dir="ltr"><<a href="mailto:medvedev.yp@gmail.com" target="_blank">medvedev.yp@gmail.com</a>></span> wrote:<br></div></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><div class="m_-4597194141808911213h5"><div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">2016-11-15 17:11 GMT+03:00 Shaun Glass <span dir="ltr"><<a href="mailto:shaunglass@gmail.com" target="_blank">shaunglass@gmail.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">proxy_redirect</blockquote></div><br>Where you terminate ssl?</div></div>
<br></div></div>______________________________<wbr>_________________<br>
nginx mailing list<br>
<a href="mailto:nginx@nginx.org" target="_blank">nginx@nginx.org</a><br>
<a href="http://mailman.nginx.org/mailman/listinfo/nginx" rel="noreferrer" target="_blank">http://mailman.nginx.org/mailm<wbr>an/listinfo/nginx</a><br></blockquote></div><br></div>
<br>______________________________<wbr>_________________<br>
nginx mailing list<br>
<a href="mailto:nginx@nginx.org" target="_blank">nginx@nginx.org</a><br>
<a href="http://mailman.nginx.org/mailman/listinfo/nginx" rel="noreferrer" target="_blank">http://mailman.nginx.org/mailm<wbr>an/listinfo/nginx</a><br></blockquote></div><br></div>
</div></div><br>______________________________<wbr>_________________<br>
nginx mailing list<br>
<a href="mailto:nginx@nginx.org">nginx@nginx.org</a><br>
<a href="http://mailman.nginx.org/mailman/listinfo/nginx" rel="noreferrer" target="_blank">http://mailman.nginx.org/<wbr>mailman/listinfo/nginx</a><br></blockquote></div><br></div>