0
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 1 year has passed since last update.

Nginx で TCP と UDP のプロキシサーバーを作る

0
Posted at

はじめに

自宅サーバー (Minecraft) を公開するときに、自宅 IP を秘匿するためにプロキシサーバーをクラウドに組んでみました。そのとき、TCP と UDP の両方とも必要だったので、両方に対応した形のサーバーを建てた時の手順です。

nginx をインストールする

apt update
vi /etc/apt/sources.list.d/nginx.list

nginx のソースを記載する

/etc/apt/sources.list.d/nginx.list
deb https://nginx.org/packages/ubuntu/ jammy nginx
deb-src https://nginx.org/packages/ubuntu/ jammy nginx

キーを追加してパッケージを更新し、nginx をインストールする

apt-key adv --keyserver keyserver.ubuntu.com --recv-keys ABF5BD827BD9BF62 
apt update
apt install nginx

nginx の設定を変更する

vi /etc/nginx/nginx.conf
/etc/nginx/nginx.conf
# 省略

http {
# 省略
}

# 以下追記
stream {
    log_format proxy '$remote_addr [$time_local] '
                     '$protocol $status $bytes_sent $bytes_received '
                     '$session_time "$upstream_addr" '
                     '"$upstream_bytes_sent" "$upstream_bytes_received" "$upstream_connect_time"';

     upstream server_tcp { # 名前は自由
        server YOUR_SERVER_IP:PORT; # プロキシ先の IP と PORT
    }

    upstream server_udp { # 名前は自由
        server YOUR_SERVER_IP:PORT; # プロキシ先の IP と PORT
    }

    server { # TCP
        error_log /var/log/nginx/error_PORT.log debug; # ログファイル名は自由
        access_log /var/log/nginx/access_PORT.log proxy buffer=32k; # ログファイル名は自由
        listen PORT; # 開放するポート
        proxy_pass server_tcp; # upstream 名にプロキシする
        proxy_timeout 60s;
    }

    server { # UDP
        error_log /var/log/nginx/error_PORT.log debug; # ログファイル名は自由
        access_log /var/log/nginx/access_PORT.log proxy buffer=32k; # ログファイル名は自由
        listen PORT udp; # 開放するポート
        proxy_pass server_udp; # upstream 名にプロキシする
        proxy_timeout 60s;
    }
}

nginx.conf の syntax を確認する

nginx -t

nginx の再起動

systemctl restart nginx

iptables のポート開放を行う

vi /etc/sysconfig/iptables
# 開放したいポートを指定して追記する
# PORT 部分を書き換える
-A INPUT -p tcp -m tcp --dport PORT -j ACCEPT
-A INPUT -p udp -m udp --dport PORT -j ACCEPT
iptables-restore < /etc/sysconfig/iptables

ルーター等のファイヤーウォールを設定する

後は各々の環境で、ルーターのファイヤーウォールなどに穴を開ける

以上!

お疲れ様でした!

参考

0
1
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?