Advertisement
niklep

Untitled

Jun 10th, 2021
840
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Nginx 1.31 KB | None | 0 0
  1. upstream admhmansy {
  2.     server 192.168.212.96 max_fails=2 fail_timeout=600s; # WAF-vIP
  3.     server 127.0.0.1:8888 backup;                        # bitrix
  4. }
  5.  
  6.  
  7. server {
  8.     listen 80;
  9.     server_name admhmansy.ru;
  10.    
  11.     return 301 https://$host$request_uri;
  12.  
  13. }
  14.  
  15. server {
  16.  
  17.     listen 443 ssl http2;
  18.     server_name admhmansy.ru;
  19.  
  20.     ssl_protocols TLSv1.2 TLSv1.3;
  21.     ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
  22.    
  23.     ssl_certificate             /path/to/cert/cert.pem;
  24.     ssl_certificate_key         /path/to/key/key.key;
  25.  
  26.     add_header X-XSS-Protection "1; mode=block";
  27.     add_header X-Content-Type-Options nosniff;
  28.  
  29.     access_log /var/log/nginx/admhmansy.ru/access.log;
  30.     error_log /var/log/nginx/admhmansy.ru/error.log;
  31.  
  32.     location / {
  33.         proxy_pass http://admhmansy;   ##### здесь убедись, что apache принимает http, а не https
  34.         proxy_set_header Host "admhmansy.ru";
  35.         proxy_set_header X-Real-IP $remote_addr;
  36.         proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  37.         proxy_set_header X-Forwarded-Proto $scheme;
  38.     }
  39.    
  40. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement