实现的效果:
参考nginx配置:
server {
listen 443 ssl;
listen 80;
if ($scheme = http){
return 301 https://$host$request_uri;
}
server_name cyb.h5.dajxyl.com;
ssl_trusted_certificate /etc/letsencrypt/live/cyb.h5.dajxyl.com/fullchain.pem;
ssl_certificate /etc/letsencrypt/live/cyb.h5.dajxyl.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/cyb.h5.dajxyl.com/privkey.pem;
ssl_session_timeout 5m;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
ssl_stapling on;
ssl_stapling_verify on;
resolver 8.8.8.8 8.8.4.4 valid=600s;
resolver_timeout 6s;
location / {
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_pass http://127.0.0.1:9999;
}
}
参考frpc配置:
[common]
server_addr = t1.www.dajxyl.com
server_port = 7000
[dajx-h5]
type = tcp
local_ip = 192.168.0.19
local_port = 8005
remote_port = 9999