释放小七猫的分享欲

喵!我是小七猫,我会把我从主人那学到的技术都教给你

我还会给你表演才艺

  • 年龄: 27
  • 称呼: 他

Tags

  • Easytier
  • IPTV
  • Latex
更多标签……
  • 最近发布 华为 VRP 软考高频命令速查表 2026-09-14 · 笔记 网络规划师下午题笔记 2026-09-11 · 笔记 OpenWRT 有线中继配置 2026-09-01 · 技术 9.26 重庆湘渝结合简约趣味婚礼仪式流程 2026-08-20 · 笔记 OpenWRT 使用 SmartDNS 优化解析速度及域名劫持 2026-08-15 · 技术
  • 所有分类 共 5 个分类 技术 123 篇 小说 23 篇 笔记 14 篇 随笔 9 篇 学术 1 篇
  • >点这儿查看全部文章
  • >欢迎来看看我的知乎

欢迎来到小七猫的博客~!

品种:银渐层-银点

爱好:睡觉、吃饭

被揍频率:2/day

我喜欢的东西:

  • 猫:4 年养猫经验
  • 编程:6 年编程经验
  • 吉他:13 年吉他演奏经验

ImmortalWrt Nginx 纯 HTTP(仅 80 端口)配置

tags: 软路由, OpenWRT
@ 09/07/2026

ImmortalWrt Nginx 纯 HTTP(仅 80 端口)配置

前置说明

  1. 默认存在 _lan(443 HTTPS 站点)、_redirect2ssl(80 强制跳转 HTTPS),全部删除彻底禁用 HTTPS
root@IWrt:~# uci show nginx
nginx.global=main
nginx.global.uci_enable='true'
nginx._lan=server
nginx._lan.listen='443 ssl default_server' '[::]:443 ssl default_server'
nginx._lan.server_name='_lan'
nginx._lan.include='restrict_locally' 'conf.d/*.locations'
nginx._lan.uci_manage_ssl='self-signed'
nginx._lan.ssl_certificate='/etc/nginx/conf.d/_lan.crt'
nginx._lan.ssl_certificate_key='/etc/nginx/conf.d/_lan.key'
nginx._lan.ssl_session_cache='shared:SSL:32k'
nginx._lan.ssl_session_timeout='64m'
nginx._lan.access_log='off; # logd openwrt'
nginx._redirect2ssl=server
nginx._redirect2ssl.listen='80' '[::]:80'
nginx._redirect2ssl.server_name='_redirect2ssl'
nginx._redirect2ssl.return='302 https://hostrequest_uri'
  1. 新建 http_luci 站点仅监听 IPv4/IPv6 80 端口,无 443 端口 https 监听
  2. restrict_locally 仅允许内网访问 LuCI 后台,外网拦截
  3. 单站点关闭 access_log,全局日志关闭
  4. 最终效果:仅 HTTP 80 访问 LuCI,无 HTTPS、无跳转、日志关闭、内网防护生效

删除原生配置

# 1. 删除原生HTTPS站点、80转HTTPS跳转站点,彻底清除443与强制跳转
uci delete nginx._lan # 如果需要 https,可以不删除 _lan_
uci delete nginx._redirect2ssl

(可选)如果需要重建 https 支持

#!/bin/bash
# 1. 创建命名server段 https_lan
uci set nginx._lan=server

# 2. 监听443 SSL IPv4 + IPv6
uci set nginx._lan.listen='443 ssl default_server'
uci add_list nginx._lan.listen='[::]:443 ssl default_server'

# 3. 站点标识
uci set nginx._lan.server_name='_lan'

# 4. 内网限制 + LuCI路由转发(和原生_lan一致)
uci set nginx._lan.include='restrict_locally'
uci add_list nginx._lan.include='conf.d/*.locations'

# 5. 自动生成自签SSL证书
uci set nginx._lan.uci_manage_ssl='self-signed'

# 6. 证书路径(uci会自动生成,无需手动改)
uci set nginx._lan.ssl_certificate='/etc/nginx/conf.d/_lan.crt'
uci set nginx._lan.ssl_certificate_key='/etc/nginx/conf.d/_lan.key'

# 7. SSL会话缓存配置
uci set nginx._lan.ssl_session_cache='shared:SSL:32k'
uci set nginx._lan.ssl_session_timeout='64m'

# 8. 关闭访问日志
uci set nginx._lan.access_log='off; # logd openwrt'

# 保存uci配置
uci commit nginx

# 重启nginx,自动生成证书并加载HTTPS站点
service nginx restart

# 校验配置
uci show nginx.https_lan
nginx -T -c /etc/nginx/uci.conf

http 支持

#!/bin/sh
# 1. 创建http_only服务段(类型server)
uci set nginx.http_only=server

# 2. 配置监听端口:IPv4 80 + IPv6 [::]:80,仅HTTP无SSL
uci set nginx.http_only.listen='80'
uci add_list nginx.http_only.listen='[::]:80'

# 3. 自定义站点标识server_name
uci set nginx.http_only.server_name='http_only'

# 4. 引入内网IP限制规则(仅局域网能访问路由器后台)
# 引入LuCI页面必需的location转发规则,缺失会404无法打开后台
uci set nginx.http_only.include='restrict_locally'
uci add_list nginx.http_only.include='conf.d/*.locations'

# 5. 当前站点关闭访问日志
uci set nginx.http_only.access_log='off'

# 6. 全局关闭Nginx访问日志(双重关闭,彻底不生成日志)
uci set nginx.global.access_log='off'

# 7. 保存所有UCI配置写入数据库
uci commit nginx

# 8. 重启Nginx重载配置生成新 /etc/nginx/uci.conf
service nginx restart

# 9. 校验最终uci配置(可选,查看是否写入成功)
uci show nginx

# 10. 校验Nginx配置语法(可选,排查报错)
nginx -T -c /etc/nginx/uci.conf

最终生效配置说明(对应执行完后的 uci show 输出)

nginx.global=main
nginx.global.uci_enable='true'
nginx.global.access_log='off'
### https 看情况
nginx._lan=server
nginx._lan.listen='443 ssl default_server' '[::]:443 ssl default_server'
nginx._lan.server_name='_lan'
nginx._lan.include='restrict_locally' 'conf.d/*.locations'
nginx._lan.uci_manage_ssl='self-signed'
nginx._lan.ssl_certificate='/etc/nginx/conf.d/_lan.crt'
nginx._lan.ssl_certificate_key='/etc/nginx/conf.d/_lan.key'
nginx._lan.ssl_session_cache='shared:SSL:32k'
nginx._lan.ssl_session_timeout='64m'
nginx._lan.access_log='off; # logd openwrt'
### https 看情况
nginx.http_only=server
nginx.http_only.listen='80' '[::]:80'
nginx.http_only.server_name='http_only'
nginx.http_only.include='restrict_locally' 'conf.d/*.locations'
nginx.http_only.access_log='off'

关键踩坑点总结(你操作中遇到的问题)

  1. 错误参数 listen6:OpenWrt Nginx UCI 无 listen6,IPv6 端口统一用 listen '[::]:80',使用 listen6 会报 nginx 语法错误
  2. enabled='0' 无效:Nginx 不识别 enabled 指令,直接 uci delete 删除 HTTPS 段是唯一彻底禁用方案
  3. 单站点 access_log 生效条件:新版模板支持 server 段独立 access_log,全局 global.access_log 同步关闭双重保险
  4. uci add 语法:uci add nginx server http_luci,不能颠倒参数顺序
  5. 多条 listen/include 配置:单值用 set,追加多条必须用 add_list
  6. 修改 uci 后必须执行 service nginx restart,才会重新渲染 /etc/nginx/uci.conf 生效

  • ««
  • «
  • 16
  • 17
  • 18
  • 19
  • 20
  • »
  • »»