You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAProxy无SSL证书下基于SNI的流量转发配置请求

HAProxy TCP 转发配置(基于SNI路由)

这是符合你需求的完整HAProxy配置,因为HAProxy不持有SSL证书,我们采用SSL透传(TCP层转发)的方式,直接根据SNI字段将流量路由到对应后端:

global
    log /dev/log local0
    log /dev/log local1 notice
    chroot /var/lib/haproxy
    stats socket /run/haproxy/admin.sock mode 660 level admin expose-fd listeners
    stats timeout 30s
    user haproxy
    group haproxy
    daemon

defaults
    log global
    mode tcp
    option tcplog
    timeout connect 5000
    timeout client 50000
    timeout server 50000

frontend https_in
    bind *:440
    bind *:443
    tcp-request inspect-delay 5s
    tcp-request content accept if { req_ssl_hello_type 1 }

    # 匹配所有example1.com及其子域名
    use_backend backend_example1 if { req_ssl_sni -m end .example1.com }
    # 匹配所有example2.com及其子域名
    use_backend backend_example2 if { req_ssl_sni -m end .example2.com }
    # 其余SNI流量默认转发到IP3
    default_backend backend_other

backend backend_example1
    server example1_server IP1:443 check

backend backend_example2
    server example2_server IP2:443 check

backend backend_other
    server other_server IP3:443 check

关键配置说明

  1. 全局/默认配置

    • mode tcp:指定HAProxy工作在TCP模式,因为我们不需要解析HTTPS内容,只是转发SSL流量。
    • 日志和超时设置:保持默认即可,用于故障排查和资源管理。
  2. 前端监听

    • bind *:440/bind *:443:让HAProxy监听服务器的440和443端口,接收外部HTTPS连接。
    • tcp-request inspect-delay 5s:给HAProxy足够时间读取SSL握手包中的SNI信息。
    • req_ssl_sni -m end .example1.com:通过后缀匹配,覆盖example1.com主域名和所有子域名(如subbbx.example1.com)。
  3. 后端配置

    • 将IP1/IP2/IP3替换为你的实际后端服务器IP地址。
    • check参数:让HAProxy定期检测后端服务器的可用性,自动剔除故障节点。

注意事项

  • 确保HAProxy服务器的防火墙允许440、443端口的入站流量,同时允许HAProxy访问后端服务器的443端口。
  • 后端服务器必须持有对应SNI的合法SSL证书,客户端会直接与后端服务器完成SSL握手,HAProxy仅负责流量转发。

内容的提问来源于stack exchange,提问作者Soda120

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 21:55:05