实际情况如何解决服务器80端口被运营商封掉问题 如何解决无公网ip如何假设web服务器作者技术方案组长 鸣鸣

服务器商  时间:2021-05-07  阅读:()

如何解决服务器80端口被运营商封掉问题

如何解决无公网ip如何假设web服务器

一.拓扑图

二.原理

假设:国内web服务器service2的web端口是990国外服务器service1开启了80端口.

通过架设虚拟局域网将国内web服务器990端口映射转发到国外服务器80端口上达到访问国内web服务器上的网站且不需要输入端口访问.

利用openvpn将service1和service2组建成一个虚拟局域网.虚拟局域网ip需要固定.所以openvpn必须分配给service1虚拟ip是固定的.将service2上的web服务器监听分配给它的虚拟ip.同时service1必须开启80端口,并且开启路由转发功能.当客户端访service1的80端口时.service1就通过路由转发功能将请求包通过虚拟虚拟局域网80端口发送给service2的web端口990上.service2获取到请求后将web数据在通过内网ip的990端口路由转发给service1的80端口上.然后提交给客户端.这样用户访问的就是

国内服务器上的网站.解决了服务器无公网ip和运营商未开启80端口如何将网站强制通过80端口发布出去.也同时解决了无固定公网ip的问题

且.使用的是骨干节点网络service2和service1建议.的请求速度取决于两者间的网络环境service2和Service1

必须是光纤。

三.操作步骤service1和service2以linux系统为主。因为稳定且设置生效不用重启服务器

1。

# php/及数据库服务安装服务apache和–y /yum install httpd mysql-server mysql php php-mysql#service httpd restart /启动apache服务/

#service mysqld restart /mysql服务/

#chkconfig httpd on /设置apache开机启动/

#chkconfig mysqld on /设置mysql开启启动/

#vim/etc/h ttpd/conf/h ttpd.conf /配置apache/

将监听端口修改成990并保存退出

#service httpd restart /启动apache服务/

测试

在浏览器中输入网址加端口号看是否架设成功出现下面内容就说明架设成功。 

op e n vp nhttp://apt.sw.be/redhat/el6/en/i386/rpmforge/RPMS/rpmforge-release-0.5.2-2.el6.rf.i686.rpminstall openvpn y#yum–/安装服务/

#cp-R/usr/share/doc/openvpn-2.2.2/easy-rsa/etc/openvpn

#cd/etc/openvpn/easy-rsa/2.0

*

#chmod+x

/到/etc/openvpn并添加可执行权限 easy-rsa/先将脚本copy

#cd/etc/openvpn/easy-rsa/2.0

#ln-s openssl-1.0.0.cnf openssl.cnf

/然后使用/easy-rsa的脚本产生证书

#vim vars

编辑所需的参数再调用之也可以默认参数

#source vars

下面这个命令在第一次安装时可以运行以后在添加客户端时千万别运行这个命令会清除所有已经生成的证书密钥。 #./clean-all

//清理所有

#./b uild-ca

/

证书/生成服务器端ca

Generating a 1024 bit RSA private key

............++++++

..................++++++writing newprivate key to'ca.key'

-----

You are about to be asked to enter information that will be incorporatedinto your certificate request.

Whatyou are about to enter is what is called a Distinguished Name or a DN.

There are quite a few fields butyou can leave some blank

For some fields there will be a default value,

Ifyou enter'. ', the field will be left blank.

-----

Country Name(2 letter code)[CN]:

State or Province Name(full name)[SH]:

Locality Name(eg,city)[PD]:

Organization Name(eg,company)[zyfmaster]:

Organizational Unit Name(eg,section)[]:zyfmaster

Common Name(eg,your name oryour server's hostname)[zyfmaster CA]:server

Name[]:

Email Address[905407204@qq.com]:

#./build-key-server server

/生成服务器端密钥key,后面这个s e rver就是服务器名可以自定义。/Generating a 1024 bit RSA private key

.......................................++++++

.......++++++writing new private key to'server.key'

-----

You are about to be asked to enter information that willbe incorporatedin to your certifica te request.

Whatyou are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields butyou can leave some blank

Forsome fields there will be a default value,

Ifyou enter'. ', the field will be left blank.

Country Name(2 letter code)[CN]:

State or Province Name(full name)[SH]:

Locality Name(eg,city)[PD]:

Organiza tion Name(eg,company)[zyfmaster]:

Organizational Unit Name(eg,section)[]:zyfmaster

Common Name(eg,your name or your server's hostname)[server]:serverName[]:

Email Address[905407204@qq.com]:

Please enter the following'extra'attributesto be sent with your certificate request

A challenge password[]:abcd1234

An optional company name[]:zyfmaster

Using configuration from/etc/openvpn/2.0/openssl.cnf

Check that the request matches the signature

Signa ture ok

The Subject's Distinguished Name is as followsco un tryNa m e :PRIN TA BL E:'CN' #可以默认也可以根据实际情况填写sta te OrPro vinceName :PRINTABLE:'SH' #可以默认也可以根据实际情况填写localityName :PRINTA BLE:'PD' #可以默认也可以根据实际情况填写organiza tionName :PRINTABLE:'zyfmaster'#可以默认也可以根据实际情况填写organiza tionalUnitName:PRINTABLE:'zyfmaster'#可以默认也可以根据实际情况填写commonName :PRINTABLE:'server' #可以默认也可以根据实际情况填写emailAddress :IA5STRING:'905407204@qq.com' #可以默认也可以根据实际情况填写

Certificate is to be certified until Dec 204:14:342022 GMT(3650 days)

Sign the certificate?[y/n]:y

#这里注意一定要选择y否则证书生成的是空证书

1 out of 1 certificate requests certified,commit?[y/n]y #这里注意一定要选择y否则证书生成的是空证书

Write out database with 1 new entries

Data Base Updated

/服务器端证书生成成功/

#./build-key client1

/生成客户端key后面这个client1就是客户端名可以自定义/

Generating a 1024 bit RSA private key

............++++++

........................................................++++++writing newprivate key to'client1.key'

You are about to be asked to enter information that will be incorporatedinto your certificate request.

Whatyou are about to enter is what is called a Distinguished Name or a DN.

There are quite a few fields butyou can leave some blank

For some fields there will be a default value,

Ifyou enter'. ', the field will be left blank.

-----

Country Name(2 letter code)[CN]:

State or Province Name(full name)[SH]:

Locality Name(eg,city)[PD]:

Organiza tion Name(eg,company)[zyfmaster]:

Organizational Unit Name(eg,section)[]:zyfmaster

Common Name(eg,your name oryour server's hostname)[client1]:client1#重要:每个不同的client生成的证书,名字必须不同.

Name[]:

Email Address[905407204@qq.com]:

Please enter the following'extra'attributesto be sent with your certificate request

A challenge password[]:abcd1234

An optional company name[]:zyfmaster

Using configuration from/etc/openvpn/2.0/openssl.cnf

Check that the request matches the signature

Signa ture ok

The Subject's Distinguished Name is as followscoun tryNam e :PRINTA BLE:'CN'sta te OrPro vinceName :PRINTABLE:'SH' #可以默认也可以根据实际情况填写localityName :PRINTA BLE:'PD' #可以默认也可以根据实际情况填写organiza tionName :PRINTABLE:'zyfmaster' #可以默认也可以根据实际情况填写organiza tionalUnitName:PRINTABLE:'zyfmaster' #可以默认也可以根据实际情况填写commonName :PRINTABLE:'clien t1' #可以默认也可以根据实际情况填写emailA ddress :IA5STRING:'905407204@qq.com' #可以默认也可以根据实际情况填写

Certificate is to be certified until Dec 204:15:502022 GMT(3650 days)

Sign the certificate?[y/n]:y

/这里注意一定要选择y否则证书生成的是空证书/

1 out of 1 certificate requests certified,commit?[y/n]y

/这里注意一定要选择y否则证书生成的是空证书/

Write out database with 1 new entries

Data Base Updated

/客户端证书生成成功/

#./build-key client2

#./build-key client3

/以此类推建立其他客户端key/

#./b uild-dh

/生成Diffie Hellman参数 这里等待一段时间。等待时长和你服务器性能决定/

#tar zcvfyskeys.tar.gz keys/*

/将keys下的所有文件打包下载到本地(可以通过winscp,http,ftp等等……)/

#cp-r/usr/share/doc/open vpn-2.2.2/sample-config-files/server.conf/etc/open vpn/

#vim/etc/open vpn/server.conf

/

配置文件service.conf创建服务端配置文件并修改/

;local a.b.c.d

改成local 192. 168.2.3port 1194 根据自己实际情况修改proto udp 根据自己实际情况修改dev tun 根据自己实际情况修改ca ca.crtcert server.crtkey server.key #This file should be kept secret

改成ca/etc/open vpn/easy-rsa/2.0/keys/ca.crt 根据自己存放证书位置修改cert/etc/openvpn/easy-rsa/2.0/keys/server.crt 根据自己存放证书位置修改

spinservers($89/月),圣何塞10Gbps带宽服务器,达拉斯10Gbps服务器

spinservers是Majestic Hosting Solutions LLC旗下站点,主要提供国外服务器租用和Hybrid Dedicated等产品的商家,数据中心包括美国达拉斯和圣何塞机房,机器一般10Gbps端口带宽,高配置硬件,支持使用PayPal、信用卡、支付宝或者微信等付款方式。目前,商家针对部分服务器提供优惠码,优惠后达拉斯机房服务器最低每月89美元起,圣何塞机房服务器最低每月...

香港E3 16G 390元/ 香港E5*2 32G 600元/ 香港站群 4-8C 1200元/ 美国200G高防 900/ 日本100M 700元

3C云国内IDC/ISP资质齐全商家,与香港公司联合运营, 已超6年运营 。本次为大家带来的是双12特惠活动,香港美国日本韩国|高速精品|高防|站群|大带宽等产品齐全,欢迎咨询问价。3C云科技有限公司官方网站:http://www.3cccy.com/客服QQ:937695003网页客服:点击咨询客户QQ交流群:1042709810价目表总览升级内存 60元 8G内存升级硬盘 1T机械 90元 2...

触摸云 26元/月 ,美国200G高防云服务器

触摸云触摸云(cmzi.com),国人商家,有IDC/ISP正规资质,主营香港线路VPS、物理机等产品。本次为大家带上的是美国高防2区的套餐。去程普通线路,回程cn2 gia,均衡防御速度与防御,防御值为200G,无视UDP攻击,可选择性是否开启CC防御策略,超过峰值黑洞1-2小时。最低套餐20M起,多数套餐为50M,适合有防御型建站需求使用。美国高防2区 弹性云[大宽带]· 配置:1-16核· ...

服务器商为你推荐
程序微信5三星iphone支持ipad更新iphone重庆网通重庆联通网上营业厅手机版windows键是哪个Win键是什么?itunes备份怎样用itunes备份iphoneipad上网ipad上网速度很慢怎么回事?fusioncharts如何自定义FusionCharts图表上的工具提示?iphonewifi苹果手机怎样设置Wi-Fi静态IP?
vps是什么 vps服务器 vps安全设置 域名备案流程 nerd tightvnc 申请空间 免费个人空间申请 中国电信测速112 有益网络 isp服务商 中国网通测速 香港新世界中心 超级服务器 raid10 空间首页登陆 空间登录首页 架设邮件服务器 789 腾讯数据库 更多