如何为Apache添加新端口并仅让Varnish监听80端口
Got it, let's walk through this step by step to get your setup working exactly how you want it. Here's what you need to do:
First, we'll set Apache up to handle two things: the existing backend traffic for Varnish, and a new port with its own document root.
Update Apache's listening ports
Locate your Apache port config file—on Debian/Ubuntu it's/etc/apache2/ports.conf, on RHEL/CentOS it's/etc/httpd/conf/httpd.conf. Add a new line for your desired port (let's use8081as an example; pick any unused port):Listen 8081Make sure you keep the existing listen port (usually
8080—this is what Varnish will forward requests to).Create a dedicated VirtualHost for the new port
In your Apache sites directory (Debian/Ubuntu:/etc/apache2/sites-available/; RHEL/CentOS:/etc/httpd/conf.d/), create a new config file likenew-port.confwith these contents:<VirtualHost *:8081> ServerName your-domain.com # Replace with your domain or server IP DocumentRoot /var/www/new-docroot # Your new document root path # Optional: Set directory permissions (adjust as needed) <Directory /var/www/new-docroot> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted </Directory> # Optional: Logging for debugging ErrorLog ${APACHE_LOG_DIR}/new-port-error.log CustomLog ${APACHE_LOG_DIR}/new-port-access.log combined </VirtualHost>Enable the new site & restart Apache
For Debian/Ubuntu, runsudo a2ensite new-port.confto enable the site, then restart Apache:sudo systemctl restart apache2For RHEL/CentOS, just restart the service directly:
sudo systemctl restart httpdVerify Apache is listening
Check that Apache is running on both ports with:sudo netstat -tulpn | grep apache2 # Use "httpd" for RHEL/CentOSYou should see entries for both your original port (e.g.,
8080) and the new8081.
Next, we'll make sure Varnish takes over port 80 and forwards traffic to Apache's main backend port.
Set Varnish to listen on port 80
Find your Varnish config file—on Debian/Ubuntu it's/etc/default/varnish, on RHEL/CentOS it's/etc/varnish/varnish.params. Look for theDAEMON_OPTS(orVARNISH_LISTEN_PORT) setting and ensure it's set to listen on port 80:DAEMON_OPTS="-a :80 \ -T localhost:6082 \ -f /etc/varnish/default.vcl \ -S /etc/varnish/secret \ -s malloc,256m"The key part here is
-a :80—this tells Varnish to only listen on port 80.Point Varnish's backend to Apache
Open/etc/varnish/default.vcland confirm the backend is set to Apache's main port (e.g.,8080):backend default { .host = "127.0.0.1"; .port = "8080"; }Restart Varnish
Apply the changes with:sudo systemctl restart varnishVerify Varnish is only listening on port 80:
sudo netstat -tulpn | grep varnishdYou should only see an entry for
0.0.0.0:80.
Let's confirm everything works as expected:
- Test Varnish on port 80: Visit
http://your-domain.com(or your server IP). Usecurl -I http://your-domain.comto check the response headers—you'll see aVia: 1.1 varnishline if Varnish is handling the request. - Test Apache's new port: Visit
http://your-domain.com:8081. This should load content from your new document root directly, with no Varnish header in the response.
- Firewall rules: Don't forget to open ports 80 and 8081 in your firewall (ufw, firewalld, etc.). For example, with ufw:
sudo ufw allow 80/tcp sudo ufw allow 8081/tcp - Port conflicts: Ensure your new port isn't used by another service—run
sudo ss -tulpn | grep :8081; no output means it's free. - Permissions: Make sure Apache's user (usually
www-data) has access to your new document root:sudo chown -R www-data:www-data /var/www/new-docroot sudo chmod -R 755 /var/www/new-docroot
内容的提问来源于stack exchange,提问作者fireplus

