You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Let's Encrypt的Nginx反向代理突然失效,求助排查

Nginx反向代理443端口连接超时排查方案

问题背景

在Debian系统部署Web应用,监听8443端口,通过Certbot配置Let's Encrypt证书,直接访问https://example.com:8443正常。使用Nginx做反向代理实现https://example.com访问,该配置运行多年后突然失效:80端口的HTTP转HTTPS重定向正常,但443端口无法访问,浏览器和curl均报连接超时。Nginx日志无错误,尝试添加include /etc/letsencrypt/options-ssl-nginx.conf;和重装Certbot均无效。

Nginx配置文件/etc/nginx/sites-available/default内容如下:

server {
    listen 80 default_server;
    server_name www.example.com example.com;
    return 301 https://example.com$request_uri;
}

server {
    listen 443 ssl default_server;
    server_name www.example.com example.com;

    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; # managed by Certbot

    location / {
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header Host $host;
            proxy_set_header X-NginX-Proxy true;
            proxy_pass https://localhost:8443/;
            proxy_redirect http://localhost:8443/ https://localhost:8443/;
    }
   
    error_page 502 /502.html;
   
    location /502.html {
        root /var/www/html;
    }
}

排查步骤与解决方案

1. 确认443端口是否被Nginx监听

执行命令检查Nginx是否成功绑定443端口:

ss -tulpn | grep nginx
  • 若输出无:443记录,先排查端口占用:
    ss -tulpn | grep :443
    
    找到占用进程后停止该进程或修改其端口。
  • 手动校验Nginx配置语法:
    nginx -t
    
    根据提示修正配置错误后重启Nginx。

2. 检查防火墙与安全组规则

连接超时大概率是流量被阻断,先检查系统防火墙:

ufw status
  • 若无443/tcp ALLOW规则,添加并重启防火墙:
    ufw allow 443/tcp
    ufw reload
    
  • 若为云服务器,同步检查服务商安全组,确保443端口入站规则已开启。

3. 验证Nginx到本地8443的连通性

直接访问8443正常不代表Nginx进程能连通,在服务器上执行测试:

curl -I https://localhost:8443 --cacert /etc/letsencrypt/live/example.com/fullchain.pem
  • 若出现SSL信任错误,在Nginx的location /块中添加证书信任配置:
    proxy_ssl_trusted_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    proxy_ssl_verify on;
    proxy_ssl_verify_depth 2;
    
  • 临时关闭验证测试(测试后需恢复,存在安全风险):
    proxy_ssl_verify off;
    

4. 检查SSL配置兼容性

确保Certbot的SSL配置文件生效:

  • 先确认文件存在:
    ls -l /etc/letsencrypt/options-ssl-nginx.conf
    
  • 在443 server块顶部添加该行,重启Nginx:
    systemctl restart nginx
    
  • 用openssl测试SSL握手:
    openssl s_client -connect example.com:443
    
    若握手失败,需调整SSL协议配置(确保启用TLS 1.2/1.3)。

5. 查看Nginx详细日志

journalctl无报错不代表日志无细节,查看访问和错误日志:

tail -f /var/log/nginx/access.log /var/log/nginx/error.log

发起访问请求后,根据日志中的记录定位问题(如请求是否到达Nginx、反向代理时的错误)。

6. 排查系统更新影响

突然失效可能和近期软件更新有关:

  • 检查证书有效期:
    certbot certificates
    
    若过期,重新签发:
    certbot renew --force-renewal
    
  • 查看Nginx版本:nginx -v,若更新后出现问题,可尝试回滚到之前的稳定版本。

内容的提问来源于stack exchange,提问作者MadsPH

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 01:24:31