When you don’t want to enable SSL offloading so both internet facing web site and the one behind reverse proxy are access over SSL you will receive domain name mismatch.
The solution is simple. Either:
- enable SSL Offloading
- enable Require Server Name Indication in bindings settings: