You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Windows Server 2022配置Nginx反向代理通过外部IP路由流量

问题描述

在Windows Server 2022上搭建Nginx反向代理,目标是让用户访问服务器25400端口时显示https://example.com的内容,但要求Nginx发往https://example.com的流量通过指定外部IP路由,而非服务器默认自身IP。

已完成的配置:

  • 监听25400端口
  • 将请求代理至https://example.com
  • 配置SSL及各类请求头

现有nginx.conf配置如下:

worker_processes 1;
pid logs/nginx.pid;

events {
    worker_connections 1024;
}

http {
    include       mime.types;
    default_type  application/octet-stream;

    server {
    listen 25400;

    location / {
        proxy_pass https://www.example.com;

        proxy_buffers 8 16k;
        proxy_buffer_size 32k;

        proxy_ssl_server_name on;
        proxy_ssl_verify on;
        proxy_ssl_verify_depth 2;
        
        proxy_ssl_trusted_certificate ca-certificates.crt;

        proxy_ssl_certificate cert.pem;
        proxy_ssl_certificate_key cert.key;

        proxy_redirect off;
        proxy_intercept_errors on;
        proxy_hide_header Location;
        proxy_hide_header Refresh;
        proxy_hide_header Strict-Transport-Security;
        proxy_cookie_domain www.example.com localhost;
        proxy_cookie_path / /;
        proxy_cookie_flags ~ Secure HttpOnly SameSite=None;
        add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
        add_header Pragma "no-cache";
        add_header Expires "0";
        sub_filter '<meta http-equiv="refresh"' '<!-- removed meta refresh -->';
        sub_filter 'https://www.example.com' 'http://localhost:25400';
        sub_filter_once off;
        add_header Access-Control-Allow-Origin *;
        add_header Access-Control-Allow-Methods 'GET, POST, OPTIONS';
        add_header Access-Control-Allow-Headers 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
        add_header Access-Control-Expose-Headers 'Content-Length,Content-Range';
        if ($request_method = OPTIONS) {
            add_header Access-Control-Origin *;
            add_header Access-Control-Allow-Methods 'GET, POST, OPTIONS';
            add_header Access-Control-Allow-Headers 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
            add_header Access-Control-Max-Age 1728000;
            return 204;
        }
        proxy_connect_timeout 120s;
        proxy_read_timeout 300s;
        proxy_send_timeout 300s;
        gzip on;
        gzip_types text/plain text/css application/javascript application/json application/xml text/xml text/javascript;
        gzip_vary on;
        proxy_buffering off;
    }

    location @no_redirects {
        return 200 "Redirect Blocked!";
    }

    location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ {
        expires off;
        add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
        proxy_pass https://www.example.com;
        proxy_hide_header Cache-Control;
    }
    
    location ~* \.svg$ {
        proxy_pass https://www.example.com;
        proxy_hide_header Cache-Control;
    }
  }
}

补充信息:

  • Nginx版本:[请填写你的版本]
  • 外部IP地址:[请提供IP或说明未配置]

解决方案

要实现Nginx通过指定外部IP路由流量,分两种场景处理:

场景1:指定外部IP是服务器本地绑定的公网IP

如果该外部IP是Windows Server上已配置的网卡IP(比如多IP绑定),直接在Nginx的location块中添加proxy_bind指令,强制Nginx用指定IP作为请求源IP:

修改后的核心配置示例

在所有包含proxy_pass https://www.example.com的location块中添加:

proxy_bind 你的外部IP地址;

比如修改主location /块:

location / {
    proxy_pass https://www.example.com;
    proxy_bind 123.45.67.89; # 替换为你的外部IP
    # 其他原有配置保持不变...
}

同时对静态资源的location块做相同修改:

location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ {
    expires off;
    add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
    proxy_pass https://www.example.com;
    proxy_bind 123.45.67.89; # 替换为你的外部IP
    proxy_hide_header Cache-Control;
}

场景2:指定外部IP是网关/路由出口IP(服务器未直接绑定)

如果该外部IP是网络出口的网关IP,需要通过Windows系统路由表强制访问example.com的流量走指定路由:

步骤1:获取example.com的IP

在Windows命令提示符中执行:

nslookup www.example.com

记录返回的目标IP(比如93.184.216.34)

步骤2:添加静态路由

执行以下命令(替换123.45.67.89为你的外部网关IP,93.184.216.34为example.com的IP):

route add 93.184.216.34 mask 255.255.255.255 123.45.67.89

如果需要永久生效(重启服务器后保留),加上-p参数:

route -p add 93.184.216.34 mask 255.255.255.255 123.45.67.89

验证路由

执行route print查看路由表,确认目标IP的路由已指向指定外部IP。


验证方法

配置完成后重启Nginx,可通过以下方式验证:

  1. 用Wireshark抓包,查看Nginx发往example.com的数据包源IP是否为指定的外部IP;
  2. 若代理的站点支持显示访问IP(如whatismyip.com类站点),直接访问服务器25400端口,查看显示的IP是否符合要求。

内容的提问来源于stack exchange,提问作者Rais

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 08:32:25