基于域名通过Squid代理转发HTTP(S)请求至对应LXC容器的配置故障排查咨询
基于域名通过Squid代理转发HTTP(S)请求至对应LXC容器的配置故障排查咨询
看起来你现在的核心问题是混淆了Squid的透明拦截模式和反向代理模式,同时缺少域名到后端容器的绑定规则,还有HTTPS请求的处理逻辑没跟上。我帮你一步步梳理问题并给出修正方案:
一、先调整Proxmox主机的iptables规则
你之前把SSH(22)端口也转发到Squid了,这完全没必要(除非你要代理SSH,但你的需求是Web服务),先把这条多余的规则删掉,同时确保IP转发功能开启:
# 删除不必要的22端口转发规则 iptables -t nat -D PREROUTING -i vmbr0 -p tcp --dport 22 -j DNAT --to 192.168.2.253:3128 # 保留Web服务的端口转发 iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport 80 -j DNAT --to 192.168.2.253:3128 iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport 443 -j DNAT --to 192.168.2.253:3129 iptables -t nat -A POSTROUTING -o vmbr0 -j MASQUERADE # 开启IP转发(临时生效,重启后需要写入sysctl.conf永久生效) echo 1 > /proc/sys/net/ipv4/ip_forward
二、重构Squid配置为反向代理模式
你之前用了http_port 3128 intercept,这是透明拦截模式,适合做网关级的上网代理,但不适合按域名转发的反向代理场景。我们改成标准的反向代理配置,同时添加域名到后端的绑定规则:
编辑Squid主配置文件(通常是/etc/squid/squid.conf):
# 基础配置:监听3128端口处理HTTP请求 http_port 3128 # 监听3129端口处理HTTPS请求(配合SNI转发) http_port 3129 ssl-bump ssl-preread # 允许内网访问(公网环境建议限制IP段,比如只允许你的公网IP) http_access allow all visible_hostname squid.proxy # 1. 定义域名ACL acl domain_example1 dstdomain .example1.com acl domain_example2 dstdomain .example2.com acl domain_example3 dstdomain .example3.com # 剩下两个域名同理添加:acl domain_exampleX dstdomain .exampleX.com # 2. 定义HTTPS的SNI ACL(用于识别HTTPS请求的域名) acl sni_example1 ssl::server_name .example1.com acl sni_example2 ssl::server_name .example2.com acl sni_example3 ssl::server_name .example3.com # 剩下两个域名同理添加 # 3. 配置后端容器节点 # HTTP后端(指向容器的80端口) cache_peer 192.168.2.225 parent 80 0 no-query name=server1_http cache_peer 192.168.2.230 parent 80 0 no-query name=server2_http cache_peer 192.168.2.235 parent 80 0 no-query name=server3_http # 剩下两个容器同理添加 # HTTPS后端(指向容器的443端口,ssl参数表示Squid和后端走HTTPS) cache_peer 192.168.2.225 parent 443 0 no-query ssl name=server1_https cache_peer 192.168.2.230 parent 443 0 no-query ssl name=server2_https cache_peer 192.168.2.235 parent 443 0 no-query ssl name=server3_https # 剩下两个容器同理添加 # 4. 关键:绑定域名ACL到对应后端 # HTTP请求转发规则 cache_peer_access server1_http allow domain_example1 cache_peer_access server1_http deny all cache_peer_access server2_http allow domain_example2 cache_peer_access server2_http deny all cache_peer_access server3_http allow domain_example3 cache_peer_access server3_http deny all # 剩下两个同理添加 # HTTPS请求转发规则(基于SNI) cache_peer_access server1_https allow sni_example1 cache_peer_access server1_https deny all cache_peer_access server2_https allow sni_example2 cache_peer_access server2_https deny all cache_peer_access server3_https allow sni_example3 cache_peer_access server3_https deny all # 剩下两个同理添加 # 禁用缓存(我们只做转发,不需要缓存Web内容) cache deny all
三、验证配置并重启服务
- 检查Squid配置是否有语法错误:
squid -k parse
- 重启Squid服务:
systemctl restart squid
四、额外检查项
- 确保后端LXC容器的Apache配置正确,域名绑定到了对应的虚拟主机,并且允许来自Squid服务器(192.168.2.253)的请求。
- 如果后端容器用的是HTTPS,要确保容器内的Apache已经配置了正确的SSL证书,并且监听443端口。
这样配置后,访问example1.com的HTTP/HTTPS请求就会被转发到192.168.2.225的对应端口,其他域名同理。
备注:内容来源于stack exchange,提问作者kzpm
相关产品推荐
相关产品推荐

