You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用独立Nginx实现多虚拟机的SSL端口复用与反向代理?

Absolutely, Nginx is the perfect tool for this job—it’ll act as a central reverse proxy, handling all SSL traffic on port 443 and routing requests to your different backend servers based on their domain names. Let’s walk through exactly how to set this up for your specific environment:

Prerequisites to Prep First

  • SSL Certificate: Make sure you have a certificate that covers all your domains (kodysalak.com, mail.kodysalak.com, help.kodysalak.com). A wildcard certificate (*.kodysalak.com) works perfectly here, or a multi-domain SAN cert if you prefer.
  • Network Connectivity: Confirm your Nginx server (10.40.1.18) can reach all backend VMs—run ping 10.40.1.12, ping 10.40.1.17, and ping 10.40.1.14 from the Nginx machine to verify no network blocks are in place.
  • Nginx Modules: Most modern CentOS Nginx packages include the required proxy_pass module by default, but if you run into issues later, double-check that http_proxy is enabled in your core config.

Step 1: Redirect All HTTP Traffic to HTTPS

First, we’ll set up a catch-all server block to forward any port 80 requests to HTTPS (since all your backends use SSL). Create a file like /etc/nginx/conf.d/redirect_http.conf with this content:

server {
    listen 80;
    server_name kodysalak.com mail.kodysalak.com help.kodysalak.com;
    return 301 https://$host$request_uri;
}

Step 2: Configure SSL Termination & Domain Routing

Next, we’ll create separate server blocks for each domain to handle SSL and route traffic to the correct backend. This keeps your config clean and easy to maintain. Create a file /etc/nginx/conf.d/domain_routing.conf with the following:

Main Apache Site (kodysalak.com)

server {
    listen 443 ssl;
    server_name kodysalak.com;

    # Update these paths to where your SSL cert/key are stored
    ssl_certificate /etc/nginx/ssl/kodysalak_com.crt;
    ssl_certificate_key /etc/nginx/ssl/kodysalak_com.key;

    # Secure SSL settings (adjust if needed for legacy clients)
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    location / {
        proxy_pass http://10.40.1.12; # Forward to your Apache server's HTTP port
        # Pass important headers to the backend
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Exchange Server (mail.kodysalak.com)

Exchange can be a bit finicky with proxies, so we’ll add some extra settings here:

server {
    listen 443 ssl;
    server_name mail.kodysalak.com;

    ssl_certificate /etc/nginx/ssl/kodysalak_com.crt;
    ssl_certificate_key /etc/nginx/ssl/kodysalak_com.key;

    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    location / {
        proxy_pass https://10.40.1.17; # Forward to Exchange's HTTPS port
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Exchange-specific tweaks
        proxy_ssl_verify off; # Disable only if Exchange uses a self-signed cert internally
        proxy_ssl_session_reuse on;
        proxy_connect_timeout 30s;
        proxy_send_timeout 30s;
        proxy_read_timeout 30s;
    }
}

Spiceworks HelpDesk (help.kodysalak.com)

server {
    listen 443 ssl;
    server_name help.kodysalak.com;

    ssl_certificate /etc/nginx/ssl/kodysalak_com.crt;
    ssl_certificate_key /etc/nginx/ssl/kodysalak_com.key;

    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    location / {
        proxy_pass http://10.40.1.14; # Forward to Spiceworks' HTTP port
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Step 3: Test & Apply the Config

  1. Validate the config: Run nginx -t to check for syntax errors. You should see "nginx: configuration file /etc/nginx/nginx.conf test is successful" if everything is right.
  2. Reload Nginx: Apply the changes with systemctl reload nginx (this avoids downtime compared to a full restart).
  3. Update DNS: Point all your domain records (kodysalak.com, mail.kodysalak.com, help.kodysalak.com) to the public IP of your Nginx server (or ensure your router forwards port 80/443 to 10.40.1.18 if it’s behind NAT).
  4. Firewall Checks: Make sure each backend server allows incoming traffic from 10.40.1.18 on ports 80/443.

Troubleshooting Quick Tips

  • If requests fail, check Nginx’s error log at /var/log/nginx/error.log for clues.
  • Test connectivity from Nginx to each backend with curl http://10.40.1.12 (or https://10.40.1.17 for Exchange) to rule out network issues.
  • For Exchange, if you see SSL errors, either enable proxy_ssl_verify off (safe for internal use) or install Exchange’s cert on the Nginx server to trust it.
  • Verify your SSL cert covers all domains with openssl s_client -connect kodysalak.com:443 | openssl x509 -noout -text.

内容的提问来源于stack exchange,提问作者Kody Salak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:11:33