# LE client needs to bind to port 80, which I'm already using

**URL:** <https://community.letsencrypt.org/t/le-client-needs-to-bind-to-port-80-which-im-already-using/2739>\
**Category:** Help\
**Created:** [November 3, 2015, 3:48am UTC](https://community.letsencrypt.org/t/le-client-needs-to-bind-to-port-80-which-im-already-using/2739 "2015-11-03T03:48:49Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![thomas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/thomas/32/1660_2.png) [@thomas](https://community.letsencrypt.org/u/thomas)\
**Post date:** [November 5, 2015, 1:03pm UTC](https://community.letsencrypt.org/t/le-client-needs-to-bind-to-port-80-which-im-already-using/2739/10 "2015-11-05T13:03:49Z")

</div>

I propose to solve this issue as follows:

> _Note: you may want to change 9999 to a different value_

&nbsp;

1. make sure apache modules mod\_proxy and mod\_proxy\_http are enabled

> `a2enmod proxy proxy_http`

1. add the following to the mod\_proxy config file (usually /etc/apache2/mods-enabled/proxy.conf)

> `<IfModule mod_proxy.c> ProxyPass "/.well-known/acme-challenge/" "http://127.0.0.1:9999/.well-known/acme-challenge/" retry=1 ProxyPassReverse "/.well-known/acme-challenge/" "http://127.0.0.1:9999/.well-known/acme-challenge/" <Location "/.well-known/acme-challenge/"> ProxyPreserveHost On Order allow,deny Allow from all Require all granted </Location> </IfModule>`

1. if you have a local firewall running: make sure it won't block access from localhost to localhost:9999

2. run letsencrypt-auto with the http port set to 9999

> `letsencrypt-auto --agree-dev-preview --agree-tos --renew-by-default --standalone --standalone-supported-challenges http-01 --http-01-port 9999 --server https://acme-v01.api.letsencrypt.org/directory certonly -d your-domain-here.tld `

&nbsp;

That way your standard apache will recognize the request from the letsencrypt server and forward it to the letsencrypt client if it's running.

> Note: if the letsencrypt client is not running your local apache will recognize that during the proxy call and re-try to contact the local letsencrypt client only after a timeout of a minute. You can find a corresponding error message in the log. So if you try to "test" the setup using your browser make sure to wait a minute before actually running the letsencrypt client.  
> Again: If you manually call an url beginning with /.well-known/acme-challenge/ without having a letsencrypt client running at that moment and you then do not wait for a minute afterward =\> then the letsencrypt server may not be able to contact the letsencrypt client.  
> So just don't manually try to load an url beginning with /.well-known/acme-challenge/ and apache won't block the request from the letsencrypt server.  
> Added parameter `retry=1` so this should not be an issue anymore 😇

---

_[View the full topic](https://community.letsencrypt.org/t/le-client-needs-to-bind-to-port-80-which-im-already-using/2739)._
