V2Ray Server config

nginx version: nginx/1.18.0
/usr/local/nginx/conf/vhost
server {
listen 443 ssl http2;
listen [::]:443 http2;  
  ssl_certificate /usr/local/nginx/conf/ssl/ssr.us.to/fullchain.cer;
    ssl_certificate_key /usr/local/nginx/conf/ssl/ssr.us.to/ssr.us.to.key;

    ssl_protocols         TLSv1.1 TLSv1.2 TLSv1.3;
    ssl_ciphers           TLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-128-CCM-8-SHA256:TLS13-AES-128-CCM-SHA256:EECDH+CHACHA20:EECDH+CHACHA20-draft:EECDH+ECDSA+AES128:EECDH+aRSA+AES128:RSA+AES128:EECDH+ECDSA+AES256:EECDH+aRSA+AES256:RSA+AES256:EECDH+ECDSA+3DES:EECDH+aRSA+3DES:RSA+3DES:!MD5;
    server_name ssr.us.to;
    index index.html index.htm;
    root  /home/usssr;
    error_page 400 = /400.html;

    # Config for 0-RTT in TLSv1.3
    ssl_early_data on;
    ssl_stapling on;
    ssl_stapling_verify on;
    add_header Strict-Transport-Security "max-age=31536000";

    location /a99d2a1/
    {
    proxy_redirect off;
    proxy_read_timeout 1200s;
    proxy_pass http://127.0.0.1:16037;
    proxy_http_version 1.1;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_set_header Host $http_host;

    # Config for 0-RTT in TLSv1.3
    proxy_set_header Early-Data $ssl_early_data;
    }
}
server {
listen 80;
listen [::]:80;
server_name ssr.us.to;
return 301 https://ssr.us.to$request_uri;
}

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注