Nginx web server

The Nginx web server is active by default on Beckhoff RT Linux® and is used, among other things, for the Beckhoff Device Manager.

To further secure the system and restrict access via the web server, you can disable forwarding in the Nginx configuration. In Beckhoff RT Linux®, the relevant entries are configured via the file mdpwebservice-bhf.conf and the included location files.

1. Open the file mdpwebservice-bhf.conf at /etc/nginx/sites-enabled/ and check the linked location files at /usr/share/mdpwebservice-bhf/locations/.. The files should be named 00-root.conf, 10-config.conf and 20-console.conf.
2. Completely comment out the entries under location /,location /config/ and location /console/ .
# location / {
# add_header ServerHostname $hostname;
# root /usr/local/www/default;
# index index.html index.htm;
# }

# location /config/ {
# include /usr/share/mdpwebservice-bhf/errorpages.conf;
# include /usr/share/mdpwebservice-bhf/auth.conf;
# include /usr/share/mdpwebservice-bhf/proxy.conf;
# proxy_pass http://unix:/var/run/mdpwebservice-bhf/web0;
# }

# location /console/ {
# include /usr/share/mdpwebservice-bhf/errorpages.conf;
# include /usr/share/mdpwebservice-bhf/auth.conf;
# include /usr/share/mdpwebservice-bhf/proxy.conf;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_pass "http://127.0.0.1:7681/";
# }
3. Save the modifications.
4. Check your configuration with sudo /usr/sbin/nginx -t.
5. Then restart the Nginx service using sudo systemctl restart nginx .
From now on, no requests will be forwarded to the Beckhoff Device Manager.