前景提要https://hostloc.com/thread-969866-1-1.html 后来实在不会,咸鱼上,论坛上找了有10为nginx大神轮番上去炸碉堡,一个不行换一个~~~终于搞定了~~ 难点在于转发到落地鸡的配置,本地是很简单的 共享配置啊,注意一下新建的网页博客,需要在博客网站配置要加上proxy_protocol;,原来是listen 444 ssl,改成listen 444 ssl http2 proxy_protocol;
- stream {
- map $ssl_preread_server_name $name {
- 99web.domain.com localweb;
- 99tj.domain.com localtrojan;
- 99vs.domain.com 127.0.0.1:10443;
- 99ifog.domain.com 127.0.0.1:10444;
- default web;
- }
-
-
- upstream dns_upstreams {
- server 83.138.53.22x:446;
- }
-
- upstream localweb {
- server 127.0.0.1:444;
- }
-
- upstream localtrojan {
- server 127.0.0.1:441;
- }
-
- upstream localtrojan2 {
- server 127.0.0.1:442;
- }
-
-
- server{
- listen 10446 udp;
- proxy_pass dns_upstreams;
- }
-
- server {
- listen 443;
- listen [::]:443;
- proxy_pass $name;
- ssl_preread on;
- proxy_protocol on;
- }
-
- server {
- listen 127.0.0.1:441 proxy_protocol;
- proxy_pass localtrojan2;
- }
-
- server {
- listen 127.0.0.1:10443 proxy_protocol ssl;
- ssl_certificate /www/server/panel/vhost/cert/99.domain.com/fullchain.pem;
- ssl_certificate_key /www/server/panel/vhost/cert/99.domain.com/privkey.pem;
- proxy_ssl on;
- proxy_ssl_server_name on;
- proxy_pass gia.domain.com:443;
- }
-
- server {
- listen 127.0.0.1:10444 proxy_protocol ssl;
- ssl_certificate /www/server/panel/vhost/cert/99.domain.com/fullchain.pem;
- ssl_certificate_key /www/server/panel/vhost/cert/99.domain.com/privkey.pem;
- proxy_ssl on;
- proxy_ssl_server_name on;
- proxy_pass ifog.domain.com:443;
- }
-
- }
复制代码
|