HTTP负载均衡器后Squid代理的HTTP请求异常问题求助
问题:Squid代理经负载均衡器后HTTP请求失败(附HTTPS端口配置方案)
问题背景
要搭建3台Squid代理服务器部署在负载均衡器后的系统,当前Squid使用HTTP端口(8080)提供服务,同时需要获取https_port的相关配置指导。测试发现通过负载均衡器IP访问HTTPS目标URL正常,但访问HTTP目标URL时请求的域名被剥离,只剩路径,导致请求失败;直接访问Squid节点IP时,HTTP和HTTPS请求均正常。
当前Squid配置
dns_v4_first on acl loadbalancer src 174.138.123.136/32 # allow only https ports acl SSL_ports port 443 acl Safe_ports port 80 # http acl Safe_ports port 443 # https http_access deny !Safe_ports http_access deny CONNECT !SSL_ports http_access allow localhost manager http_access deny manager include /etc/squid/conf.d/*.conf auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwords auth_param basic realm proxy acl authenticated proxy_auth REQUIRED http_access allow localhost http_access allow authenticated http_access deny all http_port 8080 coredump_dir /var/spool/squid
测试现象
- 通过负载均衡器访问HTTPS目标:
curl -x http://user:pass@lb_ip:8080 https://ifconfig.me # 正常 - 通过负载均衡器访问HTTP目标:
curl -x http://user:pass@lb_ip:8080 http://ifconfig.me # 失败 - 带路径测试HTTP请求,确认域名被剥离:
curl -sx http://user:pass@lb_ip:8080 http://ifconfig.me/test | grep /test # 返回:<p>The following error was encountered while trying to retrieve the URL: <a href="/test">/test</a></p> - 直接访问Squid节点IP:
curl -x http://user:pass@direct_ip:8080 https://ifconfig.me # 正常 curl -x http://user:pass@direct_ip:8080 http://ifconfig.me # 正常
失败时的错误信息
<h1>ERROR</h1> <h2>The requested URL could not be retrieved</h2> </div> <hr> <div id="content"> <p>The following error was encountered while trying to retrieve the URL: <a href="/">/</a></p>
问题原因
负载均衡器转发HTTP请求时,可能修改了客户端发送的完整请求URL或Host头,导致Squid仅收到路径部分,无法识别目标域名;另外,Squid的http_port默认配置可能未明确指定代理模式,对来自LB的请求解析异常。
解决方案
1. 调整Squid的http_port配置
修改http_port行,添加vhost vport参数,确保Squid正确解析完整请求:
http_port 8080 vhost vport
如果是透明代理场景,可改用:
http_port 8080 transparent
2. 检查负载均衡器配置
确保LB转发HTTP请求时完整保留客户端的请求URL和Host头:
- 若用Nginx做LB,
proxy_pass需包含完整请求路径,比如:proxy_pass http://squid_backend$request_uri; - 若用云厂商LB,开启“保留客户端请求头”选项,确保Host头和完整URL传递到Squid节点。
3. 验证LB的ACL规则(可选)
确认来自LB的请求被允许,可在http_access allow authenticated前添加:
http_access allow loadbalancer
HTTPS端口(https_port)配置方案
若要让Squid支持客户端通过HTTPS连接代理,按以下步骤配置:
1. 生成SSL证书
生成自签证书(生产环境建议用正式CA证书):
mkdir -p /etc/squid/ssl openssl req -new -newkey rsa:2048 -days 365 -nodes -x509 -keyout /etc/squid/ssl/squid.key -out /etc/squid/ssl/squid.crt cat /etc/squid/ssl/squid.crt /etc/squid/ssl/squid.key > /etc/squid/ssl/squid.pem chown proxy:proxy /etc/squid/ssl/*
2. 添加https_port配置
在Squid配置中加入:
# 开启HTTPS代理端口 https_port 8443 cert=/etc/squid/ssl/squid.pem ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB # 配置SSL Bump规则 acl step1 at_step SslBump1 ssl_bump peek step1 ssl_bump bump all
3. 更新安全端口规则
将8443加入Safe_ports:
acl Safe_ports port 8443 # https proxy
验证修复
修改配置后重启Squid:
systemctl restart squid
测试HTTP请求:
curl -x http://user:pass@lb_ip:8080 http://ifconfig.me
测试HTTPS代理端口:
curl -x https://user:pass@lb_ip:8443 https://ifconfig.me
内容的提问来源于stack exchange,提问作者tbhaxor
相关产品推荐
相关产品推荐

