<div dir="ltr">А что в блоке server для конкретного хоста? Что с логом ошибок? Может 414 возвращает не nginx, а apache, который стоит за ним? Без логов этого не понять.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">чт, 28 мая 2020 г. в 09:35, FuckYouSystem <<a href="mailto:nginx-forum@forum.nginx.org">nginx-forum@forum.nginx.org</a>>:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"># Server globals<br>
user                    www-data;<br>
worker_processes        auto;<br>
worker_rlimit_nofile    65535;<br>
timer_resolution         50ms; #In order to free some CPU cycles<br>
error_log               /var/log/nginx/error.log crit;<br>
pid                     /var/run/nginx.pid;<br>
<br>
<br>
# Worker config<br>
events {<br>
        worker_connections  1024;<br>
        use                 epoll;<br>
        multi_accept        on;<br>
}<br>
<br>
<br>
http {<br>
    # Main settings<br>
    sendfile                        on;<br>
    tcp_nopush                      on;<br>
    tcp_nodelay                     on;<br>
    client_header_timeout           1m;<br>
    client_body_timeout             1m;<br>
    client_header_buffer_size       2k;<br>
    client_body_buffer_size         256k;<br>
    client_max_body_size            256m;<br>
    large_client_header_buffers     4  32m;<br>
    send_timeout                    30;<br>
    keepalive_timeout               60 60;<br>
    reset_timedout_connection       on;<br>
    server_tokens                   off;<br>
    server_name_in_redirect         off;<br>
    server_names_hash_max_size      512;<br>
    server_names_hash_bucket_size   512;<br>
<br>
<br>
    # Log format<br>
    log_format  main    '$remote_addr - $remote_user [$time_local] $request<br>
'<br>
                        '"$status" $body_bytes_sent "$http_referer" '<br>
                        '"$http_user_agent" "$http_x_forwarded_for"';<br>
    log_format  bytes   '$body_bytes_sent';<br>
    #access_log          /var/log/nginx/access.log main;<br>
    access_log off;<br>
<br>
<br>
    # Mime settings<br>
    include             /etc/nginx/mime.types;<br>
    default_type        application/octet-stream;<br>
<br>
<br>
    # Compression<br>
    gzip                on;<br>
    gzip_vary           on;<br>
    gzip_comp_level     9;<br>
    gzip_min_length     512;<br>
    gzip_buffers        8 64k;<br>
    gzip_types          text/plain text/css text/javascript text/js text/xml<br>
application/json application/javascript application/x-javascript<br>
application/xml application/xml+rss application/x-font-ttf image/svg+xml<br>
font/opentype;<br>
    gzip_proxied        any;<br>
    gzip_disable        "MSIE [1-6]\.";<br>
<br>
    # Proxy settings<br>
    proxy_redirect      off;<br>
    proxy_set_header    Host            $host;<br>
    proxy_set_header    X-Real-IP       $remote_addr;<br>
    proxy_set_header    X-Forwarded-For $proxy_add_x_forwarded_for;<br>
    proxy_pass_header   Set-Cookie;<br>
    proxy_connect_timeout   90;<br>
    proxy_send_timeout  90;<br>
    proxy_read_timeout  90;<br>
    proxy_buffers       32 4k;<br>
<br>
<br>
    # Cloudflare <a href="https://www.cloudflare.com/ips" rel="noreferrer" target="_blank">https://www.cloudflare.com/ips</a><br>
    set_real_ip_from <a href="http://103.21.244.0/22" rel="noreferrer" target="_blank">103.21.244.0/22</a>;<br>
    set_real_ip_from <a href="http://103.22.200.0/22" rel="noreferrer" target="_blank">103.22.200.0/22</a>;<br>
    set_real_ip_from <a href="http://103.31.4.0/22" rel="noreferrer" target="_blank">103.31.4.0/22</a>;<br>
    set_real_ip_from <a href="http://104.16.0.0/12" rel="noreferrer" target="_blank">104.16.0.0/12</a>;<br>
    set_real_ip_from <a href="http://108.162.192.0/18" rel="noreferrer" target="_blank">108.162.192.0/18</a>;<br>
    set_real_ip_from <a href="http://131.0.72.0/22" rel="noreferrer" target="_blank">131.0.72.0/22</a>;<br>
    set_real_ip_from <a href="http://141.101.64.0/18" rel="noreferrer" target="_blank">141.101.64.0/18</a>;<br>
    set_real_ip_from <a href="http://162.158.0.0/15" rel="noreferrer" target="_blank">162.158.0.0/15</a>;<br>
    set_real_ip_from <a href="http://172.64.0.0/13" rel="noreferrer" target="_blank">172.64.0.0/13</a>;<br>
    set_real_ip_from <a href="http://173.245.48.0/20" rel="noreferrer" target="_blank">173.245.48.0/20</a>;<br>
    set_real_ip_from <a href="http://188.114.96.0/20" rel="noreferrer" target="_blank">188.114.96.0/20</a>;<br>
    set_real_ip_from <a href="http://190.93.240.0/20" rel="noreferrer" target="_blank">190.93.240.0/20</a>;<br>
    set_real_ip_from <a href="http://197.234.240.0/22" rel="noreferrer" target="_blank">197.234.240.0/22</a>;<br>
    set_real_ip_from <a href="http://198.41.128.0/17" rel="noreferrer" target="_blank">198.41.128.0/17</a>;<br>
    set_real_ip_from 2400:cb00::/32;<br>
    set_real_ip_from 2606:4700::/32;<br>
    set_real_ip_from 2803:f800::/32;<br>
    set_real_ip_from 2405:b500::/32;<br>
    set_real_ip_from 2405:8100::/32;<br>
    set_real_ip_from 2c0f:f248::/32;<br>
    set_real_ip_from 2a06:98c0::/29;<br>
    real_ip_header     CF-Connecting-IP;<br>
<br>
<br>
    # SSL PCI Compliance<br>
    ssl_session_cache   shared:SSL:10m;<br>
    ssl_protocols       TLSv1 TLSv1.1 TLSv1.2;<br>
    ssl_prefer_server_ciphers on;<br>
    ssl_ciphers       <br>
"ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4";<br>
<br>
<br>
    # Error pages<br>
    error_page          403          /error/403.html;<br>
    error_page          404          /error/404.html;<br>
    error_page          502 503 504  /error/50x.html;<br>
<br>
<br>
    # Cache settings<br>
    proxy_cache_path /var/cache/nginx levels=2 keys_zone=cache:10m<br>
inactive=60m max_size=1024m;<br>
    proxy_cache_key "$host$request_uri $cookie_user";<br>
    proxy_temp_path  /var/cache/nginx/temp;<br>
    proxy_ignore_headers Expires Cache-Control;<br>
    proxy_cache_use_stale error timeout invalid_header http_502;<br>
    proxy_cache_valid any 1d;<br>
<br>
<br>
    # Cache bypass<br>
    map $http_cookie $no_cache {<br>
        default 0;<br>
        ~SESS 1;<br>
        ~wordpress_logged_in 1;<br>
    }<br>
<br>
<br>
    # File cache settings<br>
    open_file_cache          max=10000 inactive=30s;<br>
    open_file_cache_valid    60s;<br>
    open_file_cache_min_uses 2;<br>
    open_file_cache_errors   off;<br>
<br>
<br>
    # Wildcard include<br>
    include             /etc/nginx/conf.d/*.conf;<br>
}<br>
<br>
Posted at Nginx Forum: <a href="https://forum.nginx.org/read.php?21,288174,288178#msg-288178" rel="noreferrer" target="_blank">https://forum.nginx.org/read.php?21,288174,288178#msg-288178</a><br>
<br>
_______________________________________________<br>
nginx-ru mailing list<br>
<a href="mailto:nginx-ru@nginx.org" target="_blank">nginx-ru@nginx.org</a><br>
<a href="http://mailman.nginx.org/mailman/listinfo/nginx-ru" rel="noreferrer" target="_blank">http://mailman.nginx.org/mailman/listinfo/nginx-ru</a></blockquote></div>