You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX反向代理无活动5分钟后发RST/FIN致连接断开求助

NGINX Stream代理TCP连接5分钟无活动后主动断开问题排查与解决

问题背景

内网客户端不支持TLS1.2,通过NGINX Stream模块做反向代理,实现与公网服务器的TLS1.2加密通信:

  • 内网侧:纯TCP流量(无TLS加密)
  • 公网侧:TLS1.2加密流量

故障现象

  • 连接无活动(无数据交互)5分钟后,NGINX主动断开连接
  • NGINX错误日志无报错,访问日志显示TCP状态码200,但所有会话时长均在300秒左右
  • Wireshark抓包确认:NGINX先向公网服务器发送RST包,再向客户端发送FIN/ACK包

已完成排查

  • 配置了proxy_timeout、proxy_socket_keepalive等NGINX参数
  • 检查过系统TCP可调参数,未发现异常

当前NGINX配置

# more nginx.conf

user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;

# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;

events {
worker_connections 2048;
}

stream {
resolver 127.0.0.1;
include /etc/nginx/conf.d/*.conf;

log_format basic '$remote_addr [$time_local] '
'$protocol $status $bytes_sent $bytes_received '
'$session_time $upstream_addr'
'"$upstream_bytes_sent" "$upstream_bytes_received" "$upstream_connect_time"';

access_log /var/log/nginx/stream.access.log basic;

error_log log_file;
error_log /var/log/nginx/error_log;

server {
listen 35012;
proxy_pass X.X.X.X:35012;
proxy_timeout 86400s;
proxy_connect_timeout 1200s;
proxy_socket_keepalive on;
ssl_session_cache shared:SSL:5m;
ssl_session_timeout 30m;

# For securing TCP Traffic with upstream servers.
proxy_ssl on;
proxy_ssl_certificate /etc/ssl/certs/backend.crt;
proxy_ssl_certificate_key /etc/ssl/certs/backend.key;
proxy_ssl_protocols TLSv1.2;
proxy_ssl_ciphers HIGH:!aNULL:!MD5;

# proxy_ssl_trusted_certificate /etc/ssl/certs/trusted_ca_cert.crt;
# proxy_ssl_verify on;
proxy_ssl_verify_depth 2;

#To have NGINX proxy previously negotiated connection parameters and use a so-called abbreviated handshake - Fast
proxy_ssl_session_reuse on;

}
}

解决方案建议

1. 排查上游公网服务器的超时配置

从抓包结果看,NGINX先向上游发RST包,大概率是上游服务器先触发了300秒的无活动超时并断开连接,NGINX随之向客户端发起断开。需要确认公网服务器的TCP超时、TLS会话超时设置,若上游确实有5分钟超时,要么调整上游超时时间,要么让NGINX适配该逻辑。

2. 添加proxy_ssl_timeout参数

当前配置仅设置了proxy_timeout,但针对TLS加密的上游连接,需要单独配置proxy_ssl_timeout来控制无活动超时,该参数默认值为5分钟(300秒)。在server块中添加:

proxy_ssl_timeout 86400s;

3. 配置TCP Keepalive参数

在stream块或server块中添加TCP keepalive相关配置,让NGINX主动发送探测包,避免连接因无活动被中间设备或上游断开:

tcp_keepalive_time 60s;    # 连接无活动60秒后开始发送keepalive探测包
tcp_keepalive_intvl 15s;   # 探测包发送间隔
tcp_keepalive_probes 5;    # 连续发送5次探测包无响应则断开连接

4. 检查中间网络设备的超时规则

内网到NGINX、NGINX到公网服务器之间的防火墙、负载均衡等设备可能存在300秒的TCP超时配置,需要排查这些设备的超时设置,调整为更长时间或开启keepalive探测功能。

5. 验证proxy_socket_keepalive的生效状态

执行ss -ti命令查看NGINX与上游服务器的连接状态,确认TCP keepalive参数是否已启用,确保proxy_socket_keepalive on配置生效。

内容的提问来源于stack exchange,提问作者KSKS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 06:23:33