ARR IIS重写Home Assistant WebSocket出现400错误求助
Hey there, let's tackle this WebSocket 400 error with Home Assistant behind IIS ARR! I've dealt with similar reverse proxy setups before, so here are the key checks and fixes you should work through:
First, make sure your server is set up to handle WebSocket traffic:
- Install IIS WebSocket Protocol: Open Server Manager, go to Add Roles and Features > Web Server > Application Development, then check the
WebSocket Protocolbox and complete the installation. - Enable WebSocket Proxying in ARR: In IIS Manager, navigate to the server-level node, open
Application Request Routing Cache, clickServer Proxy Settings. CheckEnable proxy, then look for theWebSocket Supportsection and tickEnable WebSocket proxying(this option exists in recent ARR versions).
Your current rewrite rules might not be accounting for WebSocket upgrade requests. Update your rule to include these critical conditions and settings:
- Add conditions to catch WebSocket headers:
<conditions> <add input="{HTTP_UPGRADE}" pattern="websocket" /> <add input="{HTTP_CONNECTION}" pattern="upgrade" /> </conditions> - Ensure your action preserves the query string and correct path. For example, if Home Assistant's WebSocket endpoint is
/api/websocket, make sure your rule doesn't modify this path accidentally. SetappendQueryString="true"in your<action>tag.
Home Assistant needs to recognize your IIS server as a trusted proxy to accept WebSocket connections:
- Edit your
configuration.yamlfile and add/update thehttpsection:http: use_x_forwarded_for: true trusted_proxies: - 192.168.x.x # Replace with your IIS server's internal IP address cors_allowed_origins: - "https://your-external-domain.com" # Replace with your public access domain - Restart Home Assistant after saving these changes.
If you're accessing HA over HTTPS:
- Confirm your IIS site's SSL binding is using a valid certificate, and that ARR is forwarding the correct protocol headers. In your rewrite rule's
<action>tag, setscheme="https"to match your external access protocol. - Ensure Home Assistant's
base_url(if configured) matches your public domain exactly.
If the above steps don't fix it, logs will give you the exact issue:
- IIS/ARR Logs: Enable detailed logging in IIS (Site > Logging > Select detailed fields) and ARR proxy logging (Server Proxy Settings > Enable logging). Check logs in
%SystemDrive%\inetpub\logs\LogFiles\W3SVC1for clues about why the 400 error is being thrown. - Home Assistant Logs: Look at
config/home-assistant.logfor entries about rejected WebSocket connections—common issues here include untrusted proxies or CORS violations.
Give these steps a try one by one—most likely the problem is missing WebSocket support, incorrect rewrite rules, or Home Assistant not trusting your IIS proxy. Let me know if you hit any specific roadblocks while implementing these fixes!
内容的提问来源于stack exchange,提问作者SibrenB

