You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HTTP负载均衡器后Squid代理的HTTP请求异常问题求助

问题:Squid代理经负载均衡器后HTTP请求失败(附HTTPS端口配置方案)

问题背景

要搭建3台Squid代理服务器部署在负载均衡器后的系统,当前Squid使用HTTP端口(8080)提供服务,同时需要获取https_port的相关配置指导。测试发现通过负载均衡器IP访问HTTPS目标URL正常,但访问HTTP目标URL时请求的域名被剥离,只剩路径,导致请求失败;直接访问Squid节点IP时,HTTP和HTTPS请求均正常。

当前Squid配置

dns_v4_first on
acl loadbalancer src 174.138.123.136/32  

# allow only https ports
acl SSL_ports port 443
acl Safe_ports port 80          # http
acl Safe_ports port 443         # https

http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager

include /etc/squid/conf.d/*.conf
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwords
auth_param basic realm proxy

acl authenticated proxy_auth REQUIRED

http_access allow localhost
http_access allow authenticated
http_access deny all
http_port 8080
coredump_dir /var/spool/squid

测试现象

  • 通过负载均衡器访问HTTPS目标:
    curl -x http://user:pass@lb_ip:8080 https://ifconfig.me  # 正常
    
  • 通过负载均衡器访问HTTP目标:
    curl -x http://user:pass@lb_ip:8080 http://ifconfig.me   # 失败
    
  • 带路径测试HTTP请求,确认域名被剥离:
    curl -sx http://user:pass@lb_ip:8080 http://ifconfig.me/test | grep /test
    # 返回:<p>The following error was encountered while trying to retrieve the URL: <a href="/test">/test</a></p>
    
  • 直接访问Squid节点IP:
    curl -x http://user:pass@direct_ip:8080 https://ifconfig.me  # 正常
    curl -x http://user:pass@direct_ip:8080 http://ifconfig.me   # 正常
    

失败时的错误信息

<h1>ERROR</h1>
<h2>The requested URL could not be retrieved</h2>
</div>
<hr>

<div id="content">
<p>The following error was encountered while trying to retrieve the URL: <a href="/">/</a></p>

问题原因

负载均衡器转发HTTP请求时,可能修改了客户端发送的完整请求URL或Host头,导致Squid仅收到路径部分,无法识别目标域名;另外,Squid的http_port默认配置可能未明确指定代理模式,对来自LB的请求解析异常。

解决方案

1. 调整Squid的http_port配置

修改http_port行,添加vhost vport参数,确保Squid正确解析完整请求:

http_port 8080 vhost vport

如果是透明代理场景,可改用:

http_port 8080 transparent

2. 检查负载均衡器配置

确保LB转发HTTP请求时完整保留客户端的请求URL和Host头:

  • 若用Nginx做LB,proxy_pass需包含完整请求路径,比如:
    proxy_pass http://squid_backend$request_uri;
    
  • 若用云厂商LB,开启“保留客户端请求头”选项,确保Host头和完整URL传递到Squid节点。

3. 验证LB的ACL规则(可选)

确认来自LB的请求被允许,可在http_access allow authenticated前添加:

http_access allow loadbalancer

HTTPS端口(https_port)配置方案

若要让Squid支持客户端通过HTTPS连接代理,按以下步骤配置:

1. 生成SSL证书

生成自签证书(生产环境建议用正式CA证书):

mkdir -p /etc/squid/ssl
openssl req -new -newkey rsa:2048 -days 365 -nodes -x509 -keyout /etc/squid/ssl/squid.key -out /etc/squid/ssl/squid.crt
cat /etc/squid/ssl/squid.crt /etc/squid/ssl/squid.key > /etc/squid/ssl/squid.pem
chown proxy:proxy /etc/squid/ssl/*

2. 添加https_port配置

在Squid配置中加入:

# 开启HTTPS代理端口
https_port 8443 cert=/etc/squid/ssl/squid.pem ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB
# 配置SSL Bump规则
acl step1 at_step SslBump1
ssl_bump peek step1
ssl_bump bump all

3. 更新安全端口规则

将8443加入Safe_ports:

acl Safe_ports port 8443         # https proxy

验证修复

修改配置后重启Squid:

systemctl restart squid

测试HTTP请求:

curl -x http://user:pass@lb_ip:8080 http://ifconfig.me

测试HTTPS代理端口:

curl -x https://user:pass@lb_ip:8443 https://ifconfig.me

内容的提问来源于stack exchange,提问作者tbhaxor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 18:53:15