nginx如何端口复用

nginx-1.15.2 版本新增了$ssl_preread_protocol 变量,通过该变量可以使用 stream 反向代理时预先判断连接是否为ssl/tls协议或者为非ssl/tls协议,从而实现同一个端口来转发不同的业务。

nginx如何端口复用

stream_ssl_preread模块检查初始ClientHello在SSL或TLS连接消息,并且提取其可用于管理连接几个值。$ssl_preread_protocol版本1.15.2中添加的变量从消息client_version字段中捕获最新的SSL / TLS版本号ClientHello。如果消息中supported_versions存在扩展名ClientHello,则变量设置为TLSv1.2/TLSv1.3。

实例:在一台反向代理服务器上运行nginx,并监听443端口,后端有两组服务,一个为HTTPS(开启TLS1.2/1.3)网站服务,另一个为SSH 服务,我们要实现这两组服务运行在同一个端口上(配置的443端口)–入口请求由Nginx自动区分。

为简便,我这时直接使用 docker环境

nginx 版本

# docker exec -it nginx nginx -V nginx version: nginx/1.15.10 built by gcc 8.2.0 (Alpine 8.2.0) built with OpenSSL 1.1.1b  26 Feb 2019 ...<省略若干行>...

目录文件

 # tree ./nginx-with-L4-reuse/./nginx-with-L4-reuse/ ├── config│   └── nginx │       ├── conf.d │       │   └── default.conf │       ├── fastcgi.conf │       ├── fastcgi_params │       ├── mime.types │       └── nginx.conf └── docker-compose.yaml  3 directories, 6 files

docker-compose.yaml

# docker-compose.yaml version: "2.4" services:   nginx:     container_name: nginx     image: nginx:alpine     network_mode: host     volumes:       - ./config/nginx:/etc/nginx/:ro     ports:       - "443:443"     restart: always

nginx.conf

user  nginx; worker_processes  2;  error_log  /var/log/nginx/error.log warn; pid        /var/run/nginx.pid;   events {     worker_connections  1024; }  stream {     log_format stream '{"@access_time":"$time_iso8601",'         '"clientip":"$remote_addr",'         '"pid":$pid,'         '"pro":"$protocol",'         '"ssl_pro": "$ssl_preread_protocol"',         '"pro":"$protocol",'         '"stus":$status,'         '"sent":$bytes_sent,'         '"recv":$bytes_received,'         '"sess_time":$session_time,'         '"up_addr":"$upstream_addr",'         '"up_sent":$upstream_bytes_sent,'         '"up_recv":$upstream_bytes_received,'         '"up_conn_time":$upstream_connect_time,'         '"up_resp_time":"$upstream_first_byte_time",'         '"up_sess_time":$upstream_session_time}';      upstream ssh {         server 192.168.50.212:22;     }      upstream web {         server 192.168.50.215:443;     }      map $ssl_preread_protocol $upstream {         default ssh;         "TLSv1.2" web;         "TLSv1.3" web;     }      # SSH and SSL on the same port     server {         listen 443;          proxy_pass $upstream;         ssl_preread on;         access_log /var/log/nginx/stream_443.log stream;     } }

$ssl_preread_protocol 实现IP层实现了不同业务配置,在某种需求上很有意义–虽然存在功能限制。然而Tengine-2.3.0已经实现的IP层基于域名转发,或许这一特性会引入到Nginx。

更多Nginx相关技术文章,请访问Nginx使用教程栏目进行学习! 

© 版权声明
THE END
喜欢就支持一下吧
点赞12 分享