# Mautic behind reverse proxy: http or https?

**URL:** <https://forum.mautic.org/t/mautic-behind-reverse-proxy-http-or-https/31524>\
**Category:** Product Support\
**Created:** [April 2, 2024, 11:49am UTC](https://forum.mautic.org/t/mautic-behind-reverse-proxy-http-or-https/31524 "2024-04-02T11:49:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dustbro](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/dustbro/32/12770_2.png) [@dustbro](https://forum.mautic.org/u/dustbro)\
**Post date:** [April 2, 2024, 11:49am UTC](https://forum.mautic.org/t/mautic-behind-reverse-proxy-http-or-https/31524/1 "2024-04-02T11:49:40Z")

</div>

**Your software**  
My Mautic version is: 5.0.3  
My PHP version is: 8.1.27  
My Database type and version is: 10.6.16-MariaDB-0ubuntu0.22.04.1

What is the proper way to run Mautic behind a reverse proxy? Right now, I have generated an SSL certificate in NPM, and left the Mautic webserver listening on port 80. It appears to be functioning fine, but should I also generate a certificate on the Mautic server and run https between Mautic and NPM?

---

<div class="post-metadata">

**Author:** ![ekke](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ekke/32/296_2.png) [@ekke](https://forum.mautic.org/u/ekke)\
**Post date:** [April 3, 2024, 6:48am UTC](https://forum.mautic.org/t/mautic-behind-reverse-proxy-http-or-https/31524/2 "2024-04-03T06:48:46Z")

</div>

IMHO you should be fine, no need for “backhand SSL” as of today. All critical things where SSL is required are browser-side and thus agnostic of what is behind the load balancer or other reverse proxy.

---

<div class="post-metadata">

**Author:** ![marcus42](https://avatars.discourse-cdn.com/v4/letter/m/ac91a4/32.png) [@marcus42](https://forum.mautic.org/u/marcus42)\
**Post date:** [April 7, 2024, 11:35am UTC](https://forum.mautic.org/t/mautic-behind-reverse-proxy-http-or-https/31524/3 "2024-04-07T11:35:58Z")

</div>

2 possibilities;  
First, the webserver is on a private LAN  
SSL offloading is fine (depending on your internal security policies)

Second, the webserver and the proxy are using a public network (i.e. you’re using CloudFlare)  
You’ll need to use 2 SSL. One at the edge. And one on your web server.
