The Linux distribution used in this article: CentOS 6.7. Download URL:https://wiki.centos.org/Download

1. Install Nginx

Download source: wget http://nginx.org/packages/centos/6/noarch/RPMS/nginx-release-centos-6-0.el6.ngx.noarch.rpm

Install source: yum install nginx-release-centos-6-0.el6.ngx.noarch.rpm -y (note the -y parameter)

Install Nginx: yum install nginx

Start Nginx service: service nginx start

Stop Nginx service: service nginx stop

Check Nginx running status: service nginx status

Check Nginx configuration file: nginx -t

Reload configuration while service is running: nginx -s reload

Add Nginx service to auto-start: chkconfig nginx on

2. Modify Firewall Rules

Modify the firewall configuration of the host where Nginx is located: vi /etc/sysconfig/iptables, and add the port used by Nginx to the allowed list.

For example: -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT (means allowing port 80 through)

Modify the firewall configuration of the host where Tomcat is located: vi /etc/sysconfig/iptables, and add the port used by Tomcat to the allowed list.

For example: -A INPUT -m state --state NEW -m tcp -p tcp --dport 8080 -j ACCEPT (means allowing port 8080 through)

If there are multiple Tomcats on the host, add multiple rules in this way and modify the corresponding port numbers.

After saving, restart the firewall: service iptables restart

3. Tomcat Load Balancing Configuration

When Nginx starts, it loads the configuration file /etc/nginx/nginx.conf by default, and nginx.conf references all .conf files in the /etc/nginx/conf.d directory.

Therefore, you can write some custom configurations into a separate .conf file. As long as the file is placed in the /etc/nginx/conf.d directory, it is convenient for maintenance.

Create tomcats.conf: vi /etc/nginx/conf.d/tomcats.conf, the content is as follows:

upstream tomcats {
     ip_hash;
    server 192.168.0.251:8080;
     server 192.168.0.251:8081;
     server 192.168.0.251:8082;
 }

Modify default.conf: vi /etc/nginx/conf.d/default.conf, modify as follows:

#注释原有的配置
#location / {
#    root   /usr/share/nginx/html;
#    index  index.html index.htm;
#}

#新增配置默认将请求转发到tomcats.conf配置的upstream进行处理
location / {
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header REMOTE-HOST $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_pass http://tomcats; #与tomcats.conf里配置的upstream同名
}

After saving, reload the configuration:nginx -s reload

4. Static Resource Separation Configuration

Modify default.conf: vi /etc/nginx/conf.d/default.conf, add the following configuration:

#所有js,css相关的静态资源文件的请求由Nginx处理
location ~.*\.(js|css)$ {
    root    /opt/static-resources; #指定文件路径
    expires     12h; #过期时间为12小时
}
#所有图片等多媒体相关静态资源文件的请求由Nginx处理
location ~.*\.(html|jpg|jpeg|png|bmp|gif|ico|mp3|mid|wma|mp4|swf|flv|rar|zip|txt|doc|ppt|xls|pdf)$ {
    root    /opt/static-resources; #指定文件路径
    expires     7d; #过期时间为7天
}

5. Modify SELinux Security Rules

If you encounter a 502 Bad Gateway error when accessing Nginx, it may be caused by SELinux on the Nginx host restricting its HTTP access permissions. Enter the command setsebool -P httpd_can_network_connect 1 to enable the permission.

The complete configuration of the file /etc/nginx/nginx.conf is as follows:

user  nginx;
worker_processes  auto;

error_log  /var/log/nginx/error.log warn;
pid        /var/run/nginx.pid;
worker_rlimit_nofile    100000;


events {
    use epoll;
    multi_accept on; 
    worker_connections  1024;
}


http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
    #                  '$status $body_bytes_sent "$http_referer" '
    #                  '"$http_user_agent" "$http_x_forwarded_for"';

    #access_log  /var/log/nginx/access.log  main;

    sendfile        on;
    server_tokens off;
    #tcp_nopush     on;

    keepalive_timeout  65;

    gzip on;
    gzip_disable "msie6";
    gzip_static on;
    gzip_proxied any;
    gzip_min_length 1000;
    gzip_comp_level 4;
    gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript;

    include /etc/nginx/conf.d/*.conf;
}

The complete configuration of the file /etc/nginx/conf.d/default.conf is as follows:

server {
    listen       80;
    server_name  localhost;

    #charset koi8-r;
    #access_log  /var/log/nginx/log/host.access.log  main;

    #location / {
    #    root   /usr/share/nginx/html;
    #    index  index.html index.htm;
    #}

    location / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header REMOTE-HOST $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_pass http://web_servers;
    }

    location ~.*\.(js|css)$ {
        root    /opt/static-resources;
        expires     12h;
    }

    location ~.*\.(html|jpg|jpeg|png|bmp|gif|ico|mp3|mid|wma|mp4|swf|flv|rar|zip|txt|doc|ppt|xls|pdf)$ {
        root    /opt/static-resources;
        expires     7d;
    }

    #error_page  404              /404.html;

    # redirect server error pages to the static page /50x.html
    #
    error_page   500 502 503 504  /50x.html;
    location = /50x.html {
        root   /usr/share/nginx/html;
    }

    # proxy the PHP scripts to Apache listening on 127.0.0.1:80
    #
    #location ~ \.php$ {
    #    proxy_pass   http://127.0.0.1;
    #}

    # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
    #
    #location ~ \.php$ {
    #    root           html;
    #    fastcgi_pass   127.0.0.1:9000;
    #    fastcgi_index  index.php;
    #    fastcgi_param  SCRIPT_FILENAME  /scripts$fastcgi_script_name;
    #    include        fastcgi_params;
    #}

    # deny access to .htaccess files, if Apache's document root
    # concurs with nginx's one
    #
    #location ~ /\.ht {
    #    deny  all;
    #}
}

Note:If you do not have root privileges when executing commands, add sudo before the commands.