Wener Site

HAProxy Proxy Protocol

约 2 分钟阅读
bash
# 测试
# 如果协议不匹配则会
# curl: (56) Recv failure: Connection reset by peer
curl --haproxy-protocol 127.0.0.1

HAProxy

frontend
frontend http
  mode http
  bind 0.0.0.0:80 name v4
  bind :::80 name v6
  tcp-request connection expect-proxy layer4

frontend https
  mode http
  bind 127.0.0.1:443 name v4 crt /etc/haproxy/certs/frontend ssl alpn h2,http/1.1 accept-proxy
  bind :::443 name v6 crt /etc/haproxy/certs/frontend ssl v4v6 alpn h2,http/1.1 accept-proxy

frontend ssl
  mode tcp
  bind 0.0.0.0:443 name v4
  bind :::443 name v6 v4v6
  tcp-request connection expect-proxy layer4
backend
backend be
  server svr 192.168.1.2:443 check send-proxy
bash
# CURL 测试 proxy protocol
curl --haproxy-protocol 192.168.1.2
text
tcp-request connection expect-proxy layer4 if { src -f proxies.lst }

Nginx

nginx
http {
  server {
    listen 80   proxy_protocol;
    listen 443  ssl proxy_protocol;

    #set_real_ip_from 192.168.1.0/24;
    #real_ip_header proxy_protocol;
  }
}

stream {
  server {
    listen 12345 proxy_protocol;
  }
}

关联信息

反向链接和本文引用的外部资料。

References

GitHub

4 条

其他外链

2 条
最近更新commit 6b3f8ffEdit

On this page