如何使用独立Nginx实现多虚拟机的SSL端口复用与反向代理?
Absolutely, Nginx is the perfect tool for this job—it’ll act as a central reverse proxy, handling all SSL traffic on port 443 and routing requests to your different backend servers based on their domain names. Let’s walk through exactly how to set this up for your specific environment:
Prerequisites to Prep First
- SSL Certificate: Make sure you have a certificate that covers all your domains (
kodysalak.com,mail.kodysalak.com,help.kodysalak.com). A wildcard certificate (*.kodysalak.com) works perfectly here, or a multi-domain SAN cert if you prefer. - Network Connectivity: Confirm your Nginx server (10.40.1.18) can reach all backend VMs—run
ping 10.40.1.12,ping 10.40.1.17, andping 10.40.1.14from the Nginx machine to verify no network blocks are in place. - Nginx Modules: Most modern CentOS Nginx packages include the required
proxy_passmodule by default, but if you run into issues later, double-check thathttp_proxyis enabled in your core config.
Step 1: Redirect All HTTP Traffic to HTTPS
First, we’ll set up a catch-all server block to forward any port 80 requests to HTTPS (since all your backends use SSL). Create a file like /etc/nginx/conf.d/redirect_http.conf with this content:
server { listen 80; server_name kodysalak.com mail.kodysalak.com help.kodysalak.com; return 301 https://$host$request_uri; }
Step 2: Configure SSL Termination & Domain Routing
Next, we’ll create separate server blocks for each domain to handle SSL and route traffic to the correct backend. This keeps your config clean and easy to maintain. Create a file /etc/nginx/conf.d/domain_routing.conf with the following:
Main Apache Site (kodysalak.com)
server { listen 443 ssl; server_name kodysalak.com; # Update these paths to where your SSL cert/key are stored ssl_certificate /etc/nginx/ssl/kodysalak_com.crt; ssl_certificate_key /etc/nginx/ssl/kodysalak_com.key; # Secure SSL settings (adjust if needed for legacy clients) ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location / { proxy_pass http://10.40.1.12; # Forward to your Apache server's HTTP port # Pass important headers to the backend proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Exchange Server (mail.kodysalak.com)
Exchange can be a bit finicky with proxies, so we’ll add some extra settings here:
server { listen 443 ssl; server_name mail.kodysalak.com; ssl_certificate /etc/nginx/ssl/kodysalak_com.crt; ssl_certificate_key /etc/nginx/ssl/kodysalak_com.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location / { proxy_pass https://10.40.1.17; # Forward to Exchange's HTTPS port proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # Exchange-specific tweaks proxy_ssl_verify off; # Disable only if Exchange uses a self-signed cert internally proxy_ssl_session_reuse on; proxy_connect_timeout 30s; proxy_send_timeout 30s; proxy_read_timeout 30s; } }
Spiceworks HelpDesk (help.kodysalak.com)
server { listen 443 ssl; server_name help.kodysalak.com; ssl_certificate /etc/nginx/ssl/kodysalak_com.crt; ssl_certificate_key /etc/nginx/ssl/kodysalak_com.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location / { proxy_pass http://10.40.1.14; # Forward to Spiceworks' HTTP port proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Step 3: Test & Apply the Config
- Validate the config: Run
nginx -tto check for syntax errors. You should see "nginx: configuration file /etc/nginx/nginx.conf test is successful" if everything is right. - Reload Nginx: Apply the changes with
systemctl reload nginx(this avoids downtime compared to a full restart). - Update DNS: Point all your domain records (
kodysalak.com,mail.kodysalak.com,help.kodysalak.com) to the public IP of your Nginx server (or ensure your router forwards port 80/443 to 10.40.1.18 if it’s behind NAT). - Firewall Checks: Make sure each backend server allows incoming traffic from 10.40.1.18 on ports 80/443.
Troubleshooting Quick Tips
- If requests fail, check Nginx’s error log at
/var/log/nginx/error.logfor clues. - Test connectivity from Nginx to each backend with
curl http://10.40.1.12(orhttps://10.40.1.17for Exchange) to rule out network issues. - For Exchange, if you see SSL errors, either enable
proxy_ssl_verify off(safe for internal use) or install Exchange’s cert on the Nginx server to trust it. - Verify your SSL cert covers all domains with
openssl s_client -connect kodysalak.com:443 | openssl x509 -noout -text.
内容的提问来源于stack exchange,提问作者Kody Salak

