Loading

Getting 502 errors when calling application/s in CH2 fronted by a DLB (CH1) during migration phase

Date de publication: Jul 16, 2026
Description

During the application migration phase from CH1 to CH 2.0 and after switching traffic to 100% so all traffic is directed to the CH2 application, the user experienced 502 Bad Gateway errors when accessing the vanity domain. The default CH2 endpoint remained accessible, showing the problem was specific to the vanity domain path.

At DLB log level the following is observed:

 
rt=0.000 uct="-" uht="-" urt="-" ua="-" us="-"
 
At Ingress log level, the following is observed:
 
DEBUG EdgeIngress [EdgeRuntime]: HTTP_Svrlet(1000030d1d): SSL Debug - To TLS/SSL peer: TLS 1.1 Alert [2 bytes]: fatal handshake_failure
DEBUG EdgeIngress [EdgeRuntime]: HTTP_Svrlet(1000030d1d): SSL Debug - Write: Alert on write: fatal: handshake failure
DEBUG EdgeIngress [EdgeRuntime]: HTTP_Svrlet(1000030d1d): SSL Debug - SSL_accept: Error in error
DEBUG EdgeIngress [EdgeRuntime]: HTTP_Svrlet(1000030d1d): disconnectInd, state=SV_TLS_HANDLESHAKE cause=DC_PEER_PROT_ERROR duration=2 abandoned reqs=0
 
As indicated in our documentation, enable TLS 1.2 at DLB level for upstream traffic, so the communication from the DLB to Ingress is successful.
Résolution

Review the production DLB upstream TLS configuration:

 

  1. Navigate to Runtime Manager
  2. In the left In the left-hand navigation, go to the Dedicated Load Balancers section.
  3. Select the specific DLB instance that is fronting your application.
  4. Locate the "Upstream Transport Protocols" section
  5. Enable TLS 1.2 on theapp DLB and retest access through the vanity domain.
Numéro d’article de la base de connaissances

005389118

 
Chargement
Salesforce Help | Article