Ubuntu20服务器Squid代理间歇性无法连接,报错443求助
Ubuntu20服务器Squid代理间歇性无法连接,报错443求助
看起来你的Squid代理遇到了挺棘手的间歇性故障——之前运行正常,从昨天开始所有设备都连不上,重启服务能暂时恢复,但没多久又会掉链子,日志里还一直出现443相关的报错。结合你提供的日志和配置文件,我来帮你拆解下可能的问题点和解决方向:
问题背景
- 运行环境:Ubuntu 20.04服务器,已部署Squid代理
- 故障表现:代理连接突然失效,所有设备无法通过代理访问;重启
systemctl restart squid后恢复正常,但会随机再次出现无法连接的情况,日志中频繁出现443相关错误
提取的关键日志信息
1675701298.639 3531 51.159.210.175 TCP_MISS/503 538 GET https://zj.chunfafa.cc/ - HIER_DIRECT/47.75.18.48 text/xml 1675701298.347 15335 216.250.247.251 NONE/500 0 CONNECT 185.45.82.51:80 - HIER_DIRECT/185.45.82.51 - 1675701535.912 8853 158.101.167.143 TCP_TUNNEL/200 39 CONNECT 185.45.82.28:8443 - HIER_DIRECT/185.45.82.28 - 1675701535.421 0 51.159.210.97 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- - 1675701535.713 3069 176.97.210.103 TCP_TUNNEL/200 39 CONNECT xinebit.com:443 - HIER_DIRECT/45.93.201.94 - 1675701784.022 60015 193.123.32.118 NONE/503 0 CONNECT 185.45.82.130:80 - HIER_NONE/- - 1675701784.022 59943 158.101.167.143 NONE/503 0 CONNECT 37.130.194.154:80 - HIER_NONE/- - 1675701784.022 59953 193.123.32.118 NONE/503 0 CONNECT 37.130.193.12:80 - HIER_NONE/- - 1675701784.022 60015 84.246.80.166 NONE/503 0 CONNECT 83.169.194.30:465 - HIER_NONE/- - 1675701784.022 59237 146.70.52.247 NONE/503 0 CONNECT 37.130.194.154:80 - HIER_NONE/- - 1675701784.022 60014 84.17.49.109 NONE/503 0 CONNECT 37.130.193.5:443 - HIER_NONE/- - 1675701784.022 59222 193.123.32.118 NONE/503 0 CONNECT 37.130.192.12:80 - HIER_NONE/- - 1675701784.022 60014 193.123.32.118 NONE/503 0 CONNECT 185.45.83.56:443 - HIER_NONE/- - 1675701784.022 60014 146.70.52.247 NONE/503 0 CONNECT 185.45.82.26:8443 - HIER_NONE/- - 1675701784.030 6 75.119.141.2 TCP_TUNNEL/200 39 CONNECT amp-api.apps.apple.com:443 - HIER_DIRECT/23.212.232.122 -
Squid配置文件(关键非注释部分)
路径:/etc/squid/squid.conf
acl localnet src 0.0.0.1-0.255.255.255 # RFC 1122 "this" network (LAN) acl localnet src 10.0.0.0/8 # RFC 1918 local private network (LAN) acl localnet src 100.64.0.0/10 # RFC 6598 shared address space (CGN) acl localnet src 169.254.0.0/16 # RFC 3927 link-local (directly plugged) machines acl localnet src 172.16.0.0/12 # RFC 1918 local private network (LAN) acl localnet src 192.168.0.0/16 # RFC 1918 local private network (LAN) acl localnet src fc00::/7 # RFC 4193 local private network range acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines acl SSL_ports port 443 acl Safe_ports port 80 # http acl Safe_ports port 21 # ftp acl Safe_ports port 443 # https acl Safe_ports port 70 # gopher acl Safe_ports port 210 # wais acl Safe_ports port 1025-65535 # unregistered ports acl Safe_ports port 280 # http-mgmt acl Safe_ports port 488 # gss-http acl Safe_ports port 591 # filemaker acl Safe_ports port 777 # multiling http acl CONNECT method CONNECT # Deny requests to certain unsafe ports http_access allow !Safe_ports # Deny CONNECT to other than secure SSL ports http_access allow CONNECT !SSL_ports # Only allow cachemgr access from localhost http_access allow localhost manager http_access deny manager # INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS # include /etc/squid/conf.d/* # Example rule allowing access from your local networks. # Adapt localnet in the ACL section to list your (internal) IP networks # from where browsing should be allowed #http_access allow localnet http_access allow localhost # And finally deny all other access to this proxy http_access allow all # Squid normally listens to port 3128 http_port 3128 # Leave coredumps in the first cache dir coredump_dir /var/spool/squid # Add any of your own refresh_pattern entries above these. # refresh_pattern ^ftp: 1440 20% 10080 refresh_pattern ^gopher: 1440 0% 1440 refresh_pattern -i (/cgi-bin/|\?) 0 0% 0 refresh_pattern \/(Packages|Sources)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims refresh_pattern \/Release(|\.gpg)$ 0 0% 0 refresh-ims refresh_pattern \/InRelease$ 0 0% 0 refresh-ims refresh_pattern \/(Translation-.*)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims # example pattern for deb packages #refresh_pattern (\.deb|\.udeb)$ 129600 100% 129600 refresh_pattern . 0 20% 4320
问题分析与修复建议
1. 配置中的致命安全漏洞(最可能的故障原因)
你的配置里有两行完全反常识的规则:
http_access allow !Safe_ports http_access allow CONNECT !SSL_ports
正常情况下,这两行应该是deny而不是allow!这意味着你允许客户端通过代理访问所有非安全端口,这会导致你的Squid被大量恶意请求滥用——比如用来扫描端口、发送垃圾流量等,很快就会耗尽Squid的连接资源、文件句柄,最终导致合法请求无法处理,出现间歇性失效和503错误。
修复步骤:
编辑/etc/squid/squid.conf,把这两行改成:
http_access deny !Safe_ports http_access deny CONNECT !SSL_ports
然后重启Squid服务:
sudo systemctl restart squid
2. 系统资源限制不足
如果修复配置后还是出现问题,可能是Squid能使用的文件句柄数或并发连接数不够。可以检查:
- 查看当前系统的文件句柄限制:
ulimit -n
- 给Squid提高文件句柄限制:编辑
/etc/security/limits.conf,添加:
squid soft nofile 65535 squid hard nofile 65535
保存后重启服务器,或者让Squid重新加载限制。
3. DNS解析故障
日志中出现的HIER_NONE标识,说明Squid无法解析目标域名的IP地址,导致无法建立连接。可以:
- 在Squid服务器上测试DNS解析是否正常,比如:
dig zj.chunfafa.cc
- 在
squid.conf中指定可靠的公共DNS服务器,比如:
dns_nameservers 8.8.8.8 1.1.1.1
添加后重启Squid生效。
4. 缓存目录问题
检查/var/spool/squid的磁盘空间和权限:
df -h /var/spool/squid ls -ld /var/spool/squid
确保磁盘空间充足,且Squid用户对该目录有读写权限。如果空间不足,可以清理缓存或扩大磁盘。
后续监控
修复后可以用以下命令监控Squid的状态,观察是否还有异常:
squidclient mgr:info tail -f /var/log/squid/access.log
备注:内容来源于stack exchange,提问作者ibraheem mohsen
相关产品推荐
相关产品推荐

