<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><span style="background-color: rgba(255, 255, 255, 0);">I have the following file named test.stream which is being included via nginx.conf  stream { include /etc/nginx/conf.d/*.stream; }<br><br>the ssl_preread_server_name variable is not being extracted and I’m running Nginx/1.13.5 (via centos 7 nginx repo).  Any idea whats going on here?  tcpdump shows the SNI field. <br><br>nginx -V<br>nginx version: nginx/1.13.5<br>built by gcc 4.8.5 20150623 (Red Hat 4.8.5-11) (GCC) <br>built with OpenSSL 1.0.1e-fips 11 Feb 2013<br>TLS SNI support enabled<br><br><br>   map $ssl_preread_server_name $name {<br>       <a href="http://cm.example.com/" dir="ltr" x-apple-data-detectors="true" x-apple-data-detectors-type="link" x-apple-data-detectors-result="2">cm.example.com</a> cm;<br>       <a href="http://ut.example.com/" dir="ltr" x-apple-data-detectors="true" x-apple-data-detectors-type="link" x-apple-data-detectors-result="3">ut.example.com</a> ut;<br>   }<br>   upstream ut {<br>       server 10.0.0.76:9000;<br>   }<br>   upstream cm {<br>       server 10.0.0.61:9000;<br>   }<br><br>   log_format stream_routing '$remote_addr [$time_local] '<br>                         'with SNI name "$ssl_preread_server_name" '<br>                         'proxying to "$name" '<br>                         '$protocol $status $bytes_sent $bytes_received '<br>                         '$session_time';<br><br>   server {<br>        listen 443 ssl;<br><br>        #Certificate & Key .PEM Format<br>        ssl_certificate /etc/ssl/certs/internal_back.crt;<br>        ssl_certificate_key /etc/ssl/certs/internal_back.key;<br>        #CIPHERS<br>        include /etc/nginx/conf.d/tcp.common;<br><br>        proxy_pass $name;<br>        ssl_preread on;<br>        access_log /var/log/nginx/stream.log stream_routing;<br>        error_log /var/log/nginx/stream-error.log debug;<br>   }<br><br><br>stream.log shows:<br>107.0.0.186 [11/Sep/2017:20:30:22 -0700] with SNI name "" proxying to "" TCP 500 0 0 0.066<br>107.0.0.186 [11/Sep/2017:20:30:22 -0700] with SNI name "" proxying to "" TCP 500 0 0 0.048<br><br><br><br>Thank you,<br>Brian</span><br style="-webkit-text-size-adjust: auto;"></body></html>