隐藏真实服务器IP,代理多个服务器时减少域名证书重复配置
server {
listen 443 ssl;
server_name test.0x0.pub;
ssl_certificate /ssl/cert.cer;
ssl_certificate_key /ssl/cert.key;
ssl_prefer_server_ciphers on;
keepalive_timeout 60;
ssl_session_cache shared:SSL:10m;
location / {
proxy_pass http://10.10.10.1; #代理的内部服务器IP
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
add_header Front-End-Https on;
proxy_redirect off;
}
}