frontend sni
log global
mode tcp
option tcplog
tcp-request inspect-delay 5s
tcp-request connection set-src src,ipmask(16,56)
tcp-request content accept if { req_ssl_hello_type 1 }
bind ${BIND_V4}:443
bind ${BIND_V6}:443
use_backend %[req_ssl_sni,lower,map(/usr/local/etc/haproxy/sni.map)]