Welcome! Log In Create A New Profile

Advanced

RE: Proxy Pass

Reinis Rozitis
May 23, 2019 11:00AM
> Instead of IP address, if we use FQDN with https, do we have to validate the SSL certificate on Proxy_Pass?.

By default the certificate validation is turned off (and nginx just uses the ssl for traffic encryption).
If needed you can enable it with proxy_ssl_verify on; ( http://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_ssl_verify )


> Due to IP address, multiple sites on the server Nginx access log logging the same requests.

If you do the logging on the backend server (and there are multiple virtualhosts) and proxy_pass is via http://ip, then you need/have to pass also the Host header.

Either by passing the Host header from original request:

proxy_set_header Host $host;

or you can specify a custom one:

proxy_set_header Host "some.domain";



> Is the above Nginx config, correct way of doing it?.

Depends on your setup and what you want to achieve.


For example if your location blocks match the request on the backend you can omit the URI in the proxy_pass directive:

location /abc {
proxy_pass https://1.1.1.1;
}

rr

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Proxy Pass

Sathish Kumar May 23, 2019 08:36AM

RE: Proxy Pass

Reinis Rozitis May 23, 2019 11:00AM

Re: Proxy Pass

Sathish Kumar May 23, 2019 07:36PM

Re: Proxy Pass

Sathish Kumar May 23, 2019 08:06PM

Re: Proxy Pass

Sathish Kumar May 23, 2019 08:08PM

Re: Proxy Pass

Sathish Kumar May 23, 2019 09:26PM

Re: Proxy Pass

Francis Daly May 24, 2019 08:44AM

Re: Proxy Pass

Sathish Kumar May 24, 2019 08:56AM

Re: Proxy Pass

Francis Daly May 24, 2019 06:12PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 179
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready