能否跨网络部署Zabbix Server与Agent?HTTP proxy连接方案咨询
Absolutely, this setup is totally feasible—let me walk you through exactly how to make it work for your scenario where Zabbix Server is on the public internet and your 10-12 internal agents can't be reached from outside. The key here is using Zabbix Agent's active mode (since it lets agents initiate connections to the server, avoiding the "agents can't be accessed externally" problem) paired with an HTTP proxy to route those outbound requests to your public Zabbix Server.
Make sure your Zabbix Server and Agent are running version 2.4 or newer—this is when HTTP proxy support was added to Zabbix Agent. Most modern deployments (5.x, 6.x, 7.x) will meet this requirement, but it's worth double-checking.
Edit the Zabbix Agent configuration file (path varies by OS: Linux uses /etc/zabbix/zabbix_agentd.conf, Windows uses C:\Program Files\Zabbix Agent\zabbix_agentd.conf) and update these critical parameters:
Set Active Mode
Since we don't want the server to connect to agents, switch to active mode where agents send data to the server:
# ServerActive points to your public Zabbix Server's IP/domain and port (default 10051) ServerActive=your-public-zabbix-server.com:10051 # Server parameter can be set to 127.0.0.1 since it's unused in active mode Server=127.0.0.1
Enable HTTP Proxy Support
Add these lines to route agent traffic through your internal HTTP proxy:
# Replace with your proxy's internal IP/domain and port ProxyURL=http://your-internal-proxy.local:8080 # Uncomment and fill these if your proxy requires authentication # ProxyUser=proxy-username # ProxyPassword=proxy-password
Match Hostnames Exactly
Ensure the agent's hostname matches what you'll configure on the Zabbix Server—this is how the server identifies which data belongs to which host:
Hostname=Internal-Server-01 # Use the exact name you'll create in Zabbix Web UI
Restart the Agent
Apply the changes by restarting the agent service:
- Linux:
sudo systemctl restart zabbix-agent - Windows: Open Services > Find "Zabbix Agent" > Right-click > Restart
Log into your Zabbix Server's web interface and set up each internal host correctly:
- When creating a new host, set the Connect to option to
Agent (active) - Enter the exact
Hostnameyou defined in the agent's configuration file - You don't need to fill in an IP address for the agent (since it's sending data actively)
- Attach relevant templates (like
Template OS LinuxorTemplate OS Windows)—most default templates include active-mode monitoring items, so they'll work out of the box
- Check the Zabbix Agent logs (Linux:
/var/log/zabbix/zabbix_agentd.log, Windows:C:\Program Files\Zabbix Agent\zabbix_agentd.log) for lines likesending data to ServerActive[your-public-zabbix-server.com:10051]—this means the agent is successfully sending data through the proxy. - In the Zabbix Web UI, go to Monitoring > Hosts—your internal hosts should show as
Enabledwith a recentLast seentimestamp. - Check Monitoring > Latest Data to confirm metrics are being received.
- Make sure your internal HTTP proxy allows outbound traffic to your public Zabbix Server on port 10051—you may need to add a rule in the proxy's firewall or access control list.
- If using an HTTPS proxy, update
ProxyURLtohttps://your-internal-proxy.local:443and ensure the agent's system trusts the proxy's SSL certificate (for self-signed certs, you may need to add it to the system's trusted store). - Keep an eye on agent logs and server host statuses periodically to catch any connection issues early.
内容的提问来源于stack exchange,提问作者Tanya C

