frontend sni
        log             global
	mode		tcp
	option		tcplog
	tcp-request	inspect-delay 5s
	tcp-request	connection set-src src,ipmask(16,56)
	tcp-request	content accept if { req_ssl_hello_type 1 }

        bind            ${BIND_V4}:443
        bind            ${BIND_V6}:443
        use_backend     %[req_ssl_sni,lower,map(/usr/local/etc/haproxy/sni.map)]