You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu20服务器Squid代理间歇性无法连接,报错443求助

Ubuntu20服务器Squid代理间歇性无法连接,报错443求助

看起来你的Squid代理遇到了挺棘手的间歇性故障——之前运行正常,从昨天开始所有设备都连不上,重启服务能暂时恢复,但没多久又会掉链子,日志里还一直出现443相关的报错。结合你提供的日志和配置文件,我来帮你拆解下可能的问题点和解决方向:

问题背景

  • 运行环境:Ubuntu 20.04服务器,已部署Squid代理
  • 故障表现:代理连接突然失效,所有设备无法通过代理访问;重启systemctl restart squid后恢复正常,但会随机再次出现无法连接的情况,日志中频繁出现443相关错误

提取的关键日志信息

1675701298.639   3531 51.159.210.175  TCP_MISS/503 538 GET https://zj.chunfafa.cc/ - HIER_DIRECT/47.75.18.48 text/xml
1675701298.347  15335 216.250.247.251 NONE/500 0 CONNECT 185.45.82.51:80  - HIER_DIRECT/185.45.82.51 -
1675701535.912   8853 158.101.167.143 TCP_TUNNEL/200 39 CONNECT 185.45.82.28:8443  - HIER_DIRECT/185.45.82.28 -
1675701535.421      0 51.159.210.97   NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
1675701535.713   3069 176.97.210.103  TCP_TUNNEL/200 39 CONNECT xinebit.com:443    - HIER_DIRECT/45.93.201.94 -
1675701784.022  60015 193.123.32.118  NONE/503 0 CONNECT 185.45.82.130:80  - HIER_NONE/- -
1675701784.022  59943 158.101.167.143 NONE/503 0 CONNECT 37.130.194.154:80 - HIER_NONE/- -
1675701784.022  59953 193.123.32.118  NONE/503 0 CONNECT 37.130.193.12:80  - HIER_NONE/- -
1675701784.022  60015 84.246.80.166   NONE/503 0 CONNECT 83.169.194.30:465 - HIER_NONE/- -
1675701784.022  59237 146.70.52.247   NONE/503 0 CONNECT 37.130.194.154:80 - HIER_NONE/- -
1675701784.022  60014 84.17.49.109    NONE/503 0 CONNECT 37.130.193.5:443  - HIER_NONE/- -
1675701784.022  59222 193.123.32.118  NONE/503 0 CONNECT 37.130.192.12:80  - HIER_NONE/- -
1675701784.022  60014 193.123.32.118  NONE/503 0 CONNECT 185.45.83.56:443  - HIER_NONE/- -
1675701784.022  60014 146.70.52.247   NONE/503 0 CONNECT 185.45.82.26:8443 - HIER_NONE/- -
1675701784.030      6 75.119.141.2    TCP_TUNNEL/200 39 CONNECT amp-api.apps.apple.com:443 - HIER_DIRECT/23.212.232.122 -

Squid配置文件(关键非注释部分)

路径:/etc/squid/squid.conf

acl localnet src 0.0.0.1-0.255.255.255  # RFC 1122 "this" network (LAN)
acl localnet src 10.0.0.0/8         # RFC 1918 local private network (LAN)
acl localnet src 100.64.0.0/10      # RFC 6598 shared address space (CGN)
acl localnet src 169.254.0.0/16     # RFC 3927 link-local (directly plugged) machines
acl localnet src 172.16.0.0/12      # RFC 1918 local private network (LAN)
acl localnet src 192.168.0.0/16     # RFC 1918 local private network (LAN)
acl localnet src fc00::/7           # RFC 4193 local private network range
acl localnet src fe80::/10          # RFC 4291 link-local (directly plugged) machines

acl SSL_ports port 443
acl Safe_ports port 80      # http
acl Safe_ports port 21      # ftp
acl Safe_ports port 443     # https
acl Safe_ports port 70      # gopher
acl Safe_ports port 210     # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280     # http-mgmt
acl Safe_ports port 488     # gss-http
acl Safe_ports port 591     # filemaker
acl Safe_ports port 777     # multiling http
acl CONNECT method CONNECT

# Deny requests to certain unsafe ports
http_access allow !Safe_ports

# Deny CONNECT to other than secure SSL ports
http_access allow CONNECT !SSL_ports

# Only allow cachemgr access from localhost
http_access allow localhost manager
http_access deny manager

# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
#
include /etc/squid/conf.d/*

# Example rule allowing access from your local networks.
# Adapt localnet in the ACL section to list your (internal) IP networks
# from where browsing should be allowed
#http_access allow localnet
http_access allow localhost

# And finally deny all other access to this proxy
http_access allow all

# Squid normally listens to port 3128
http_port 3128

# Leave coredumps in the first cache dir
coredump_dir /var/spool/squid

# Add any of your own refresh_pattern entries above these.
#
refresh_pattern ^ftp:       1440    20% 10080
refresh_pattern ^gopher:    1440    0%  1440
refresh_pattern -i (/cgi-bin/|\?) 0 0%  0
refresh_pattern \/(Packages|Sources)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims
refresh_pattern \/Release(|\.gpg)$ 0 0% 0 refresh-ims
refresh_pattern \/InRelease$ 0 0% 0 refresh-ims
refresh_pattern \/(Translation-.*)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims
# example pattern for deb packages
#refresh_pattern (\.deb|\.udeb)$   129600 100% 129600
refresh_pattern .       0   20% 4320

问题分析与修复建议

1. 配置中的致命安全漏洞(最可能的故障原因)

你的配置里有两行完全反常识的规则:

http_access allow !Safe_ports
http_access allow CONNECT !SSL_ports

正常情况下,这两行应该是deny而不是allow!这意味着你允许客户端通过代理访问所有非安全端口,这会导致你的Squid被大量恶意请求滥用——比如用来扫描端口、发送垃圾流量等,很快就会耗尽Squid的连接资源、文件句柄,最终导致合法请求无法处理,出现间歇性失效和503错误。

修复步骤:
编辑/etc/squid/squid.conf,把这两行改成:

http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports

然后重启Squid服务:

sudo systemctl restart squid

2. 系统资源限制不足

如果修复配置后还是出现问题,可能是Squid能使用的文件句柄数或并发连接数不够。可以检查:

  • 查看当前系统的文件句柄限制:
ulimit -n
  • 给Squid提高文件句柄限制:编辑/etc/security/limits.conf,添加:
squid soft nofile 65535
squid hard nofile 65535

保存后重启服务器,或者让Squid重新加载限制。

3. DNS解析故障

日志中出现的HIER_NONE标识,说明Squid无法解析目标域名的IP地址,导致无法建立连接。可以:

  • 在Squid服务器上测试DNS解析是否正常,比如:
dig zj.chunfafa.cc
  • 在squid.conf中指定可靠的公共DNS服务器,比如:
dns_nameservers 8.8.8.8 1.1.1.1

添加后重启Squid生效。

4. 缓存目录问题

检查/var/spool/squid的磁盘空间和权限:

df -h /var/spool/squid
ls -ld /var/spool/squid

确保磁盘空间充足,且Squid用户对该目录有读写权限。如果空间不足,可以清理缓存或扩大磁盘。

后续监控

修复后可以用以下命令监控Squid的状态,观察是否还有异常:

squidclient mgr:info
tail -f /var/log/squid/access.log

备注:内容来源于stack exchange,提问作者ibraheem mohsen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 14:12:32