proxmox_nginx
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
proxmox_nginx [2016/07/17 10:14] – neoon | proxmox_nginx [2021/11/25 22:42] (current) – external edit 127.0.0.1 | ||
---|---|---|---|
Line 11: | Line 11: | ||
proxy_redirect off; | proxy_redirect off; | ||
location / { | location / { | ||
- | proxy_set_header X-Forwarded-Proto https; | + | |
proxy_pass https:// | proxy_pass https:// | ||
| | ||
Line 23: | Line 23: | ||
Make sure you replace ssl_certificate and ssl_certificate_key | Make sure you replace ssl_certificate and ssl_certificate_key | ||
- | Restart Nginx: service nginx restart, it should return no errors. | + | Restart Nginx: |
+ | | ||
Second step, Turn the pveproxy to localhost only. Copy this file to: / | Second step, Turn the pveproxy to localhost only. Copy this file to: / | ||
Line 31: | Line 32: | ||
POLICY=" | POLICY=" | ||
| | ||
- | Restart pveproxy: service pveproxy | + | You can also block it over iptables, since it does not fully work anymore on 5.x. |
+ | post-up iptables -A INPUT -p tcp --dport 8006 -s 127.0.0.0/8 -j ACCEPT #allow localhost for reverse proxy | ||
+ | post-up iptables -A INPUT -p tcp --dport 8006 -j DROP # | ||
+ | post-up iptables -A INPUT -p tcp --dport 3128 -j DROP # | ||
+ | |||
+ | |||
+ | Restart pveproxy: | ||
+ | | ||
https:// | https:// | ||
proxmox_nginx.1468750450.txt.gz · Last modified: 2021/11/25 22:43 (external edit)