You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

远程IIS服务器Ocelot网关WebSocket连接SSL握手失败求助

Ocelot网关部署远程IIS后WebSocket SSL握手失败问题排查方案

问题概述

将Ocelot API网关部署到远程IIS服务器后,WebSocket连接建立失败。本地同一机器运行时连接完全正常,但远程连接时抛出SSL/TLS握手异常:

System.Net.WebSockets.WebSocketException (0x80004005): Unable to connect to the remote server ---> System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception. ---> System.IO.IOException: Cannot determine the frame size or a corrupted frame was received.    at System.Net.Security.SslStream.GetFrameSize(ReadOnlySpan1 buffer)at System.Net.Security.SslStream.ReceiveBlobAsync[TIOAdapter](TIOAdapter adapter)at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](TIOAdapter adapter, Boolean receiveFirst, Byte[] reAuthenticationData, Boolean isApm)at System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken)

背景:使用Ocelot代理WebSocket连接至远程WebSocket服务器,已在IIS中完成WebSocket协议的安装、允许和启用配置,但问题仍未解决。


排查与解决建议

1. 验证IIS站点SSL证书有效性

  • 确认远程IIS站点绑定的SSL证书未过期、主体名称/SAN扩展与网关访问域名匹配,证书链完整(可通过浏览器访问网关HTTPS地址查看证书详情)
  • 若使用自签名证书,需将证书导入网关服务器和客户端的信任根证书存储,否则会触发SSL不信任错误

2. 修正Ocelot路由与SSL配置

  • 在ocelot.json中确保WebSocket路由的UpstreamScheme和DownstreamScheme设置为wss(目标WebSocket服务器启用SSL时),示例配置:
    {
      "Routes": [
        {
          "UpstreamPathTemplate": "/ws/{everything}",
          "UpstreamHttpMethod": ["GET"],
          "DownstreamPathTemplate": "/ws/{everything}",
          "DownstreamScheme": "wss",
          "DownstreamHostAndPorts": [
            {
              "Host": "your-websocket-server-domain",
              "Port": 443
            }
          ],
          "EnableHttp2": false,
          "WebSocketReplacement": true
        }
      ]
    }
    
  • 测试环境可临时添加SSL绕过配置(生产环境禁用),在GlobalConfiguration中加入:
    "GlobalConfiguration": {
      "BaseUrl": "https://your-ocelot-domain",
      "HttpClientHandlerOptions": {
        "ServerCertificateCustomValidationCallback": "ReturnTrue"
      }
    }
    

3. 调整IIS TLS与加密套件设置

  • 打开IIS站点绑定的SSL设置,启用TLS 1.2及以上版本,禁用SSL 3.0、TLS 1.0等旧协议
  • 使用IIS Crypto工具统一配置加密套件,确保网关与目标WebSocket服务器支持共同的加密套件,避免因套件不兼容导致握手失败

4. 排查网络层连通性

  • 检查远程IIS服务器的防火墙/安全组,确保允许WebSocket端口(wss默认443,ws默认80)的入站和出站流量
  • 在远程IIS服务器上用wscat工具测试目标WebSocket服务器连通性:
    wscat -c wss://your-websocket-server-domain/ws
    
  • 若网关前端有反向代理(如Nginx、Azure应用网关),需配置代理传递Upgrade和Connection请求头,确保WebSocket握手信号正常转发

5. 强制.NET运行时使用指定TLS版本

  • 在网关项目的启动代码中添加以下配置,强制使用TLS 1.2/1.3:
    ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls13;
    
  • 确认远程服务器安装的.NET运行时版本符合Ocelot要求(需.NET Core 3.1及以上)

内容的提问来源于stack exchange,提问作者Nimish M.S.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 22:13:19