# Invalid Response Errors

**URL:** <https://community.letsencrypt.org/t/invalid-response-errors/191037>\
**Category:** Help\
**Created:** [January 12, 2023, 7:19am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037 "2023-01-12T07:19:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 7:19am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/1 "2023-01-12T07:19:01Z")

</div>

Hello,  
We had a certificate expire. I went ahead and removed the old certs because we kept running into errors. While trying to create new certs, I get the following errors:

Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:  
Domain: [midwestrp.net](http://midwestrp.net)  
Type: unauthorized  
Detail: 147.135.105.106: Invalid response from [http://midwestrp.net/.well-known/acme-challenge/uBswgL7oeOq2urpDcRU32teP\_HYt9xypWQ25ZDz8w2I:](http://midwestrp.net/.well-known/acme-challenge/uBswgL7oeOq2urpDcRU32teP_HYt9xypWQ25ZDz8w2I:) 404

Domain: [www.midwestrp.net](http://www.midwestrp.net)  
Type: unauthorized  
Detail: 147.135.105.106: Invalid response from [http://www.midwestrp.net/.well-known/acme-challenge/1ytDUi2b\_tIHhSuAokUpk6ZuxY-Xieof4yyESsAgCwE:](http://www.midwestrp.net/.well-known/acme-challenge/1ytDUi2b_tIHhSuAokUpk6ZuxY-Xieof4yyESsAgCwE:) 404

Domain: [ia.midwestrp.net](http://ia.midwestrp.net)  
Type: unauthorized  
Detail: 147.135.105.106: Invalid response from [http://ia.midwestrp.net/.well-known/acme-challenge/mxN6zHeS1nZ8-iYWjGEydaH0f5tf5ObOmBJImykbAA0:](http://ia.midwestrp.net/.well-known/acme-challenge/mxN6zHeS1nZ8-iYWjGEydaH0f5tf5ObOmBJImykbAA0:) 502

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

I shutdown NGINX and while I did receive a CONNECTED type, I received an error regarding a potential firewall issue.

I uploaded the recent log for review.

Any ideas? All I'm trying to do is get a new SSL. Thanks!

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [midwestrp.net](http://midwestrp.net)

I ran this command: certbot certonly

It produced this output: See above

My web server is (include version): NGINX Windows, Unk Version

The operating system my web server runs on is (include version): Windows 2019 Server

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): Certbot 1.24.0

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 7:25am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/2 "2023-01-12T07:25:42Z")

</div>

It wouldn't let me upload the log, but here is the log I get when I shutdown NGINX.

Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:  
Domain: [ia.midwestrp.net](http://ia.midwestrp.net)  
Type: connection  
Detail: 147.135.105.106: Fetching [http://ia.midwestrp.net/.well-known/acme-challenge/rxf-lyxl2WhliGRKtjG7T2h2wWa5zwwGbHIRSr-wVp4:](http://ia.midwestrp.net/.well-known/acme-challenge/rxf-lyxl2WhliGRKtjG7T2h2wWa5zwwGbHIRSr-wVp4:) Timeout during connect (likely firewall problem)

Domain: [midwestrp.net](http://midwestrp.net)  
Type: connection  
Detail: 147.135.105.106: Fetching [http://midwestrp.net/.well-known/acme-challenge/JGcRRrIzia2QT4NfHi8I41e8wf2UUQYoN7jmIAF-g-w:](http://midwestrp.net/.well-known/acme-challenge/JGcRRrIzia2QT4NfHi8I41e8wf2UUQYoN7jmIAF-g-w:) Timeout during connect (likely firewall problem)

Domain: [www.midwestrp.net](http://www.midwestrp.net)  
Type: connection  
Detail: 147.135.105.106: Fetching [http://www.midwestrp.net/.well-known/acme-challenge/VCmC4huQnEQXY6P\_N2UQ91T8m0Raz8SlzuSSNk2WhGQ:](http://www.midwestrp.net/.well-known/acme-challenge/VCmC4huQnEQXY6P_N2UQ91T8m0Raz8SlzuSSNk2WhGQ:) Timeout during connect (likely firewall problem)

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 7:27am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/3 "2023-01-12T07:27:28Z")

</div>

Hi @RaffiMWRP, and welcome to the LE community forum 🙂

The 404 errors seems like you just typed in the wrong webroot.  
The 502 error is a bit more complicated...  
I'd say the name proxies to a backend that is having trouble.  
That said, if the challenge file is supposed to be handled by `nginx`, then it isn't doing that at all.

Not sure what this means:

> [@RaffiMWRP](#):
>
> I shutdown NGINX and while I did receive a CONNECTED type

You should do your testing against the staging environment [not production].  
So, add `--dry-run` to your `certbot` test - until they all pass.

That said, you will need to review the `nginx` configuration.  
Ensuring that the webroots used match the ones being served.

The newly added:

> [@RaffiMWRP](#):
>
> Timeout during connect (likely firewall problem)

seems like you've changed something in the firewall and now things have gone from bad to worse.  
HTTP must be allowed when using `HTTP-01` authentication.

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 7:42am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/4 "2023-01-12T07:42:14Z")

</div>

I am new to this server and just looking at everything and a little lost. Appreciate your help and thank you for the welcome message!

What would the webroot directory be? The server has a \Certbot directory and a \WEB\_SERVERS directory which contains NGINX.

I attempted to do the --dry-run and received the following message:

````plaintext
Saving debug log to C:\Certbot\log\letsencrypt.log

How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Spin up a temporary webserver (standalone)
2: Place files in webroot directory (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 1
Please enter the domain name(s) you would like on your certificate (comma and/or
space separated) (Enter 'c' to cancel): midwestrp.net ia.midwestrp.net www.midwestrp.net
Simulating a certificate request for midwestrp.net and 2 more domains

Certbot failed to authenticate some domains (authenticator: standalone). The Certificate Authority reported these problems:
  Domain: ia.midwestrp.net
  Type: unauthorized
  Detail: 147.135.105.106: Invalid response from http://ia.midwestrp.net/.well-known/acme-challenge/OaUB9LTr8V_WxIuQYgLE7I2pjQkBG5u-XOOSmb7w5vg: 404

  Domain: midwestrp.net
  Type: unauthorized
  Detail: 147.135.105.106: Invalid response from http://midwestrp.net/.well-known/acme-challenge/BkHXHJxuENFKPNvw7rvCa0DmsY3SVNjWu01Zzcs6wU4: 404

  Domain: www.midwestrp.net
  Type: unauthorized
  Detail: 147.135.105.106: Invalid response from http://www.midwestrp.net/.well-known/acme-challenge/uVoVpk_Kvf4QGOe7gznzfP7qJQpuY7VGrJNwleIsUoA: 404

Hint: The Certificate Authority failed to download the challenge files from the temporary standalone webserver started by Certbot on port 80. Ensure that the listed domains point to this machine and that it can accept inbound connections from the internet.

Some challenges have failed.```

How can I review the nginx configuration?

I only received the Timeout during connect message when I turned off the NGINX service. The NGINX service has been turned on now.

Thank you!
````

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 7:47am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/5 "2023-01-12T07:47:33Z")

</div>

> [@RaffiMWRP](#):
>
> What would the webroot directory be?

That can be found in the `nginx` configuration.  
Show:  
`nginx -T`

> [@RaffiMWRP](#):
>
> `The NGINX service has been turned on now.`

Then you should NOT choose #1, use #2:

> [@RaffiMWRP](#):
>
> ```nohighlight
> 1: Spin up a temporary webserver (standalone)
> 2: Place files in webroot directory (webroot)
> 
> ```

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 7:50am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/6 "2023-01-12T07:50:02Z")

</div>

I ran the nginx -t command and received the following:

PS C:\Windows\system32\> certbot --nginx -t  
Saving debug log to C:\Certbot\log\letsencrypt.log  
The requested nginx plugin does not appear to be installed

I think that's the issue, yes? How would I be able to get this plugin installed? I just find it odd because if the plugin wasn't installed, then how was our SSL Cert working prior?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 7:51am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/7 "2023-01-12T07:51:04Z")

</div>

> [@RaffiMWRP](#):
>
> `How can I review the nginx configuration?`

`nginx -T`  
But that should be the result of what the admin put in there.  
hmm...  
Aren't you the `nginx` admin?  
If so, you really should take a moment and review the basics of `nginx`.  
If not, then they should be brought into the loop - _too many cooks can ..._

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 7:51am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/8 "2023-01-12T07:51:49Z")

</div>

> [@RaffiMWRP](#):
>
> I ran the nginx -t

It is "`nginx -T`" not "`nginx -t`"  
[capital T]

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [January 12, 2023, 7:55am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/9 "2023-01-12T07:55:30Z")

</div>

Windows doesn't have the Certbot nginx plugin.

Things might have stopped working if you made your nginx configuration more complex than it was initially. If requests no longer hit the filesystem, that would cause issues.

One thing you could try is to add this in each of your nginx virtual hosts, to ensure that the Let's Encrypt validation requests are served from your filesystem rather than your web application:

```nginx
location /.well-known/acme-challenge/ {
    root "C:/WEB_SERVERS";
}

```

restart nginx, and then try:

```
certbot certonly -d example.com --webroot -w "C:/WEB_SERVERS"

```

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 7:55am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/10 "2023-01-12T07:55:33Z")

</div>

I am the admin, yes. And I am on the admin login. I apologize I might not be fully giving everything. New to this server and trying to know what was done in the past.

Trying to run the command 'certbot --nginx -T' and I received the following:

PS C:\windows\system32\> certbot --nginx -T  
usage:  
certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...

Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,  
it will attempt to use a webserver both for obtaining and installing the  
certificate.  
certbot: error: unrecognized arguments: -T

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 7:58am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/11 "2023-01-12T07:58:02Z")

</div>

> [@RaffiMWRP](#):
>
> Trying to run the command 'certbot --nginx -T'

Not: ' **certbot** --nginx -T'  
Just: **'nginx -T'**

I missed that before.

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 7:59am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/12 "2023-01-12T07:59:38Z")

</div>

I ran the command and received the following:

PS C:\windows\system32\> certbot certonly -d [midwestrp.net](http://midwestrp.net) --webroot -w "C:/WEB\_SERVERS"  
Saving debug log to C:\Certbot\log\letsencrypt.log  
Requesting a certificate for [midwestrp.net](http://midwestrp.net)

Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:  
Domain: [midwestrp.net](http://midwestrp.net)  
Type: unauthorized  
Detail: 147.135.105.106: Invalid response from [http://midwestrp.net/.well-known/acme-challenge/huCOxMnydI7TwydA9g98N\_9l7Fk4GPvvLADN3hJ50Bo:](http://midwestrp.net/.well-known/acme-challenge/huCOxMnydI7TwydA9g98N_9l7Fk4GPvvLADN3hJ50Bo:) 404

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

Some challenges have failed.

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 8:00am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/13 "2023-01-12T08:00:20Z")

</div>

the nginx -T command doesn't work. I think \_AZ mentioned that Windows doesn't have the NGINX plugin and thus that command might not work.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 8:02am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/14 "2023-01-12T08:02:16Z")

</div>

# **Please read carefully.**

Certbot for Windows doesn't have an nginx plugin.  
That is NOT what we are trying to do.  
We are trying to find the (web)root used by `nginx`.  
Go to the folder with `nginx.exe`  
And type:  
`nginx -T`  
Then put here what it spits out.

`dir c:\nginx.exe /s`

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 8:07am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/15 "2023-01-12T08:07:06Z")

</div>

Again, sorry if you have to explain it to me. Just learning. Thank you for being patient.

Here is what nginx -T spitted out:

```plaintext
C:\WEB_SERVERS\NGINX>nginx -T
nginx: the configuration file C:\WEB_SERVERS\NGINX/conf/nginx.conf syntax is ok
nginx: configuration file C:\WEB_SERVERS\NGINX/conf/nginx.conf test is successful
# configuration file C:\WEB_SERVERS\NGINX/conf/nginx.conf:

#user nobody;
worker_processes auto;

#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;

pid logs/nginx.pid;

events {
    worker_connections 1024;
}

http {
    include mime.types;
    default_type application/octet-stream;

    log_format main '$remote_addr - $ssl_server_name $remote_user [$time_local] '
                    '"$request" ($status - ${request_length}b->${body_bytes_sent}b) '
                    'in ${request_time}s "$request_body" '
                    '"$http_referer" "$http_user_agent" ';

    log_format ia '$remote_addr - $ssl_server_name $remote_user [$time_local]'
                    '"$request" ($status - ${request_length}b->${body_bytes_sent}b)'
                    'in ${request_time}s'
                    '"$http_referer" "$http_user_agent"';

    #access_log logs/access.log main;

    server_tokens off;

    sendfile on;
    tcp_nopush on;
    tcp_nodelay on;
    gzip on;

    server_names_hash_bucket_size 64;

    keepalive_timeout 65;

    include "localhost.conf";

    include "mwrp/midwestrp.net.conf";
    include "mwrp/mwrp.app.conf";

    include "mwrp/api.mwrp.app.conf";
    include "mwrp/logger.mwrp.app.conf";

    include "mwrp/portainer.mwrp.app.conf";
    include "mwrp/clickup.mwrp.app.conf";
    include "mwrp/map.mwrp.app.conf";

    server {
        listen 80;
        server_name shortener.mwrp.app;

        access_log logs/shortener.access.log main;

        set_real_ip_from 103.21.244.0/22;
        set_real_ip_from 103.22.200.0/22;
        set_real_ip_from 103.31.4.0/22;
        set_real_ip_from 104.16.0.0/13;
        set_real_ip_from 104.24.0.0/14;
        set_real_ip_from 108.162.192.0/18;
        set_real_ip_from 131.0.72.0/22;
        set_real_ip_from 141.101.64.0/18;
        set_real_ip_from 162.158.0.0/15;
        set_real_ip_from 172.64.0.0/13;
        set_real_ip_from 173.245.48.0/20;
        set_real_ip_from 188.114.96.0/20;
        set_real_ip_from 190.93.240.0/20;
        set_real_ip_from 197.234.240.0/22;
        set_real_ip_from 198.41.128.0/17;
        set_real_ip_from 2400:cb00::/32;
        set_real_ip_from 2606:4700::/32;
        set_real_ip_from 2803:f800::/32;
        set_real_ip_from 2405:b500::/32;
        set_real_ip_from 2405:8100::/32;
        set_real_ip_from 2c0f:f248::/32;
        set_real_ip_from 2a06:98c0::/29;

        real_ip_header CF-Connecting-IP;

        location ~ / {
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Forwarded-For $remote_addr;
            proxy_set_header X-Forwarded-Host $remote_addr;
            proxy_pass http://127.0.0.1:4000;
            allow all;
        }
    }

    server {
        listen 443 ssl;
        server_name shortener.mwrp.app;

        ssl_certificate certs/mwrp.crt;
        ssl_certificate_key certs/mwrp.key;

        ssl_session_cache shared:SSL:1m;
        ssl_session_timeout 5m;

        ssl_ciphers HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers on;

        access_log logs/shortener-ssl.access.log main;

        set_real_ip_from 103.21.244.0/22;
        set_real_ip_from 103.22.200.0/22;
        set_real_ip_from 103.31.4.0/22;
        set_real_ip_from 104.16.0.0/13;
        set_real_ip_from 104.24.0.0/14;
        set_real_ip_from 108.162.192.0/18;
        set_real_ip_from 131.0.72.0/22;
        set_real_ip_from 141.101.64.0/18;
        set_real_ip_from 162.158.0.0/15;
        set_real_ip_from 172.64.0.0/13;
        set_real_ip_from 173.245.48.0/20;
        set_real_ip_from 188.114.96.0/20;
        set_real_ip_from 190.93.240.0/20;
        set_real_ip_from 197.234.240.0/22;
        set_real_ip_from 198.41.128.0/17;
        set_real_ip_from 2400:cb00::/32;
        set_real_ip_from 2606:4700::/32;
        set_real_ip_from 2803:f800::/32;
        set_real_ip_from 2405:b500::/32;
        set_real_ip_from 2405:8100::/32;
        set_real_ip_from 2c0f:f248::/32;
        set_real_ip_from 2a06:98c0::/29;

        real_ip_header CF-Connecting-IP;

        location ~ / {
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Forwarded-For $remote_addr;
            proxy_set_header X-Forwarded-Host $remote_addr;
            proxy_pass http://127.0.0.1:4000;
            allow all;
        }
    }

    server {
        listen 80;
        server_name loi.mwrp.app;

        access_log logs/loi.mwrp.app.access.log main;

        set_real_ip_from 103.21.244.0/22;
        set_real_ip_from 103.22.200.0/22;
        set_real_ip_from 103.31.4.0/22;
        set_real_ip_from 104.16.0.0/13;
        set_real_ip_from 104.24.0.0/14;
        set_real_ip_from 108.162.192.0/18;
        set_real_ip_from 131.0.72.0/22;
        set_real_ip_from 141.101.64.0/18;
        set_real_ip_from 162.158.0.0/15;
        set_real_ip_from 172.64.0.0/13;
        set_real_ip_from 173.245.48.0/20;
        set_real_ip_from 188.114.96.0/20;
        set_real_ip_from 190.93.240.0/20;
        set_real_ip_from 197.234.240.0/22;
        set_real_ip_from 198.41.128.0/17;
        set_real_ip_from 2400:cb00::/32;
        set_real_ip_from 2606:4700::/32;
        set_real_ip_from 2803:f800::/32;
        set_real_ip_from 2405:b500::/32;
        set_real_ip_from 2405:8100::/32;
        set_real_ip_from 2c0f:f248::/32;
        set_real_ip_from 2a06:98c0::/29;

        real_ip_header CF-Connecting-IP;

        location ~ / {
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Forwarded-For $remote_addr;
            proxy_set_header X-Forwarded-Host $remote_addr;
            proxy_pass http://127.0.0.1:5683;
        }
    }

    server {
        listen 443 ssl;
        server_name loi.mwrp.app;

        ssl_certificate certs/mwrp.crt;
        ssl_certificate_key certs/mwrp.key;

        ssl_session_cache shared:SSL:1m;
        ssl_session_timeout 5m;

        ssl_ciphers HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers on;

        access_log logs/loi.mwrp.app.access.log main;

        set_real_ip_from 103.21.244.0/22;
        set_real_ip_from 103.22.200.0/22;
        set_real_ip_from 103.31.4.0/22;
        set_real_ip_from 104.16.0.0/13;
        set_real_ip_from 104.24.0.0/14;
        set_real_ip_from 108.162.192.0/18;
        set_real_ip_from 131.0.72.0/22;
        set_real_ip_from 141.101.64.0/18;
        set_real_ip_from 162.158.0.0/15;
        set_real_ip_from 172.64.0.0/13;
        set_real_ip_from 173.245.48.0/20;
        set_real_ip_from 188.114.96.0/20;
        set_real_ip_from 190.93.240.0/20;
        set_real_ip_from 197.234.240.0/22;
        set_real_ip_from 198.41.128.0/17;
        set_real_ip_from 2400:cb00::/32;
        set_real_ip_from 2606:4700::/32;
        set_real_ip_from 2803:f800::/32;
        set_real_ip_from 2405:b500::/32;
        set_real_ip_from 2405:8100::/32;
        set_real_ip_from 2c0f:f248::/32;
        set_real_ip_from 2a06:98c0::/29;

        real_ip_header CF-Connecting-IP;

        location ~ / {
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Forwarded-For $remote_addr;
            proxy_set_header X-Forwarded-Host $remote_addr;
            proxy_pass http://127.0.0.1:5683;
        }
    }

    server {
        listen 80;
        server_name dev-portals.mwrp.app;

        access_log logs/portals.access.log main;

        set_real_ip_from 103.21.244.0/22;
        set_real_ip_from 103.22.200.0/22;
        set_real_ip_from 103.31.4.0/22;
        set_real_ip_from 104.16.0.0/13;
        set_real_ip_from 104.24.0.0/14;
        set_real_ip_from 108.162.192.0/18;
        set_real_ip_from 131.0.72.0/22;
        set_real_ip_from 141.101.64.0/18;
        set_real_ip_from 162.158.0.0/15;
        set_real_ip_from 172.64.0.0/13;
        set_real_ip_from 173.245.48.0/20;
        set_real_ip_from 188.114.96.0/20;
        set_real_ip_from 190.93.240.0/20;
        set_real_ip_from 197.234.240.0/22;
        set_real_ip_from 198.41.128.0/17;
        set_real_ip_from 2400:cb00::/32;
        set_real_ip_from 2606:4700::/32;
        set_real_ip_from 2803:f800::/32;
        set_real_ip_from 2405:b500::/32;
        set_real_ip_from 2405:8100::/32;
        set_real_ip_from 2c0f:f248::/32;
        set_real_ip_from 2a06:98c0::/29;

        real_ip_header CF-Connecting-IP;

        location ~ / {
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Forwarded-For $remote_addr;
            proxy_set_header X-Forwarded-Host $remote_addr;
            proxy_pass http://127.0.0.1:5692;
        }
    }

    server {
        listen 443 ssl;
        server_name dev-portals.mwrp.app;

        ssl_certificate certs/mwrp.crt;
        ssl_certificate_key certs/mwrp.key;

        ssl_session_cache shared:SSL:1m;
        ssl_session_timeout 5m;

        ssl_ciphers HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers on;

        access_log logs/portals-ssl.access.log main;

        set_real_ip_from 103.21.244.0/22;
        set_real_ip_from 103.22.200.0/22;
        set_real_ip_from 103.31.4.0/22;
        set_real_ip_from 104.16.0.0/13;
        set_real_ip_from 104.24.0.0/14;
        set_real_ip_from 108.162.192.0/18;
        set_real_ip_from 131.0.72.0/22;
        set_real_ip_from 141.101.64.0/18;
        set_real_ip_from 162.158.0.0/15;
        set_real_ip_from 172.64.0.0/13;
        set_real_ip_from 173.245.48.0/20;
        set_real_ip_from 188.114.96.0/20;
        set_real_ip_from 190.93.240.0/20;
        set_real_ip_from 197.234.240.0/22;
        set_real_ip_from 198.41.128.0/17;
        set_real_ip_from 2400:cb00::/32;
        set_real_ip_from 2606:4700::/32;
        set_real_ip_from 2803:f800::/32;
        set_real_ip_from 2405:b500::/32;
        set_real_ip_from 2405:8100::/32;
        set_real_ip_from 2c0f:f248::/32;
        set_real_ip_from 2a06:98c0::/29;

        real_ip_header CF-Connecting-IP;

        location ~ / {
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Forwarded-For $remote_addr;
            proxy_set_header X-Forwarded-Host $remote_addr;
            proxy_pass http://127.0.0.1:5692;
        }
    }
}

# configuration file C:\WEB_SERVERS\NGINX/conf/mime.types:

types {
    text/html html htm shtml;
    text/css css;
    text/xml xml;
    image/gif gif;
    image/jpeg jpeg jpg;
    application/javascript js;
    application/atom+xml atom;
    application/rss+xml rss;

    text/mathml mml;
    text/plain txt;
    text/vnd.sun.j2me.app-descriptor jad;
    text/vnd.wap.wml wml;
    text/x-component htc;

    image/png png;
    image/svg+xml svg svgz;
    image/tiff tif tiff;
    image/vnd.wap.wbmp wbmp;
    image/webp webp;
    image/x-icon ico;
    image/x-jng jng;
    image/x-ms-bmp bmp;

    font/woff woff;
    font/woff2 woff2;

    application/java-archive jar war ear;
    application/json json;
    application/mac-binhex40 hqx;
    application/msword doc;
    application/pdf pdf;
    application/postscript ps eps ai;
    application/rtf rtf;
    application/vnd.apple.mpegurl m3u8;
    application/vnd.google-earth.kml+xml kml;
    application/vnd.google-earth.kmz kmz;
    application/vnd.ms-excel xls;
    application/vnd.ms-fontobject eot;
    application/vnd.ms-powerpoint ppt;
    application/vnd.oasis.opendocument.graphics odg;
    application/vnd.oasis.opendocument.presentation odp;
    application/vnd.oasis.opendocument.spreadsheet ods;
    application/vnd.oasis.opendocument.text odt;
    application/vnd.openxmlformats-officedocument.presentationml.presentation
                                                     pptx;
    application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
                                                     xlsx;
    application/vnd.openxmlformats-officedocument.wordprocessingml.document
                                                     docx;
    application/vnd.wap.wmlc wmlc;
    application/x-7z-compressed 7z;
    application/x-cocoa cco;
    application/x-java-archive-diff jardiff;
    application/x-java-jnlp-file jnlp;
    application/x-makeself run;
    application/x-perl pl pm;
    application/x-pilot prc pdb;
    application/x-rar-compressed rar;
    application/x-redhat-package-manager rpm;
    application/x-sea sea;
    application/x-shockwave-flash swf;
    application/x-stuffit sit;
    application/x-tcl tcl tk;
    application/x-x509-ca-cert der pem crt;
    application/x-xpinstall xpi;
    application/xhtml+xml xhtml;
    application/xspf+xml xspf;
    application/zip zip;

    application/octet-stream bin exe dll;
    application/octet-stream deb;
    application/octet-stream dmg;
    application/octet-stream iso img;
    application/octet-stream msi msp msm;

    audio/midi mid midi kar;
    audio/mpeg mp3;
    audio/ogg ogg;
    audio/x-m4a m4a;
    audio/x-realaudio ra;

    video/3gpp 3gpp 3gp;
    video/mp2t ts;
    video/mp4 mp4;
    video/mpeg mpeg mpg;
    video/quicktime mov;
    video/webm webm;
    video/x-flv flv;
    video/x-m4v m4v;
    video/x-mng mng;
    video/x-ms-asf asx asf;
    video/x-ms-wmv wmv;
    video/x-msvideo avi;
}

# configuration file C:\WEB_SERVERS\NGINX/conf/localhost.conf:

server {
    listen 80;
    server_name localhost;

    access_log logs/host.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        allow 127.0.0.1;
        deny all;
    }
}

server {
    listen 443 ssl;
    server_name localhost;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/host-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        allow 127.0.0.1;
        deny all;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/midwestrp.net.conf:

# rewrite ^ http://community.midwestrp.net$request_uri? permanent;

server {
    listen 80;
    server_name midwestrp.net;

    access_log logs/mwrp.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/www.midwestrp.net/;
        rewrite ^/$ https://community.midwestrp.net redirect;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name midwestrp.net;

    ssl_certificate certs/mw.crt;
    ssl_certificate_key certs/mw.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/mwrp-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/www.midwestrp.net/;
        rewrite ^/$ https://community.midwestrp.net redirect;
        allow all;
    }
}

server {
    listen 80;
    server_name www.midwestrp.net;

    access_log logs/mwrp.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/www.midwestrp.net/;
        rewrite ^/$ https://community.midwestrp.net redirect;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name www.midwestrp.net;

    ssl_certificate certs/mw.crt;
    ssl_certificate_key certs/mw.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/mwrp-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/www.midwestrp.net/;
        rewrite ^/$ https://community.midwestrp.net redirect;
        allow all;
    }
}

server {
    listen 80;
    server_name ia.midwestrp.net;

    access_log logs/ia.access.log ia;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/ia.midwestrp.net/;
        proxy_pass http://127.0.0.1:5681;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name ia.midwestrp.net;

    ssl_certificate certs/mw.crt;
    ssl_certificate_key certs/mw.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/ia-ssl.access.log ia;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/ia.midwestrp.net/;
        proxy_pass http://127.0.0.1:5681;
        allow all;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/mwrp.app.conf:
server {
    listen 80;
    server_name mwrp.app;

    access_log logs/dev.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4000;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/dev-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4000;
        allow all;
    }
}

server {
    listen 80;
    server_name mwrp.dev;

    access_log logs/dev.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4000;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name mwrp.dev;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/dev-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4000;
        allow all;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/api.mwrp.app.conf:
server {
    listen 80;
    server_name api.mwrp.app;

    access_log logs/api.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4004;
    }
}

server {
    listen 443 ssl;
    server_name api.mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/api-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4004;
    }
}

server {
    listen 80;
    server_name api-assistant-internal.mwrp.app;

    access_log logs/api-assistant-internal.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4848;
    }
}

server {
    listen 443 ssl;
    server_name api-assistant-internal.mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/api-assistant-internal-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4848;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/logger.mwrp.app.conf:

server {
    listen 80;
    server_name logger.mwrp.app;

    access_log logs/logger.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4002;
        allow 127.0.0.1;
        allow 147.135.105.106;
        deny all;
    }
}

server {
    listen 443 ssl;
    server_name logger.mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/logger-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:4002;
        allow 127.0.0.1;
        allow 147.135.105.106;
        deny all;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/portainer.mwrp.app.conf:

server {
    listen 80;
    server_name manage.mwrp.app;

    access_log logs/manage.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass https://127.0.0.1:9443;
    }
}

server {
    listen 443 ssl;
    server_name manage.mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/manage-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass https://127.0.0.1:9443;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/clickup.mwrp.app.conf:
server {
    listen 80;
    server_name clickup.mwrp.app;

    access_log logs/clickup.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:5682;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name clickup.mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/clickup-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        proxy_pass http://127.0.0.1:5682;
        allow all;
    }
}
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/map.mwrp.app.conf:
server {
    listen 80;
    server_name livemap.mwrp.app;

    access_log logs/livemap.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/www.midwestrp.net/;
        rewrite ^/$ https://map.mwrp.app redirect;
        allow all;
    }
}

server {
    listen 443 ssl;
    server_name livemap.mwrp.app;

    ssl_certificate certs/mwrp.crt;
    ssl_certificate_key certs/mwrp.key;

    ssl_session_cache shared:SSL:1m;
    ssl_session_timeout 5m;

    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    access_log logs/livemap-ssl.access.log main;

    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 131.0.72.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2c0f:f248::/32;
    set_real_ip_from 2a06:98c0::/29;

    real_ip_header CF-Connecting-IP;

    location ~ / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Host $remote_addr;
        #root ./html/www.midwestrp.net/;
        rewrite ^/$ https://map.mwrp.app redirect;
        allow all;
    }
}

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 8:07am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/16 "2023-01-12T08:07:12Z")

</div>

Did you skip over the first part below?

> [@\_az](#):
>
> One thing you could try is to add this in each of your nginx virtual hosts, to ensure that the Let's Encrypt validation requests are served from your filesystem rather than your web application:
> 
> ```nohighlight
> location /.well-known/acme-challenge/ {
> root "C:/WEB_SERVERS";
> }
> 
> ```
> 
> restart nginx, and then try:
> 
> ```nohighlight
> certbot certonly -d example.com --webroot -w "C:/WEB_SERVERS"
> 
> ```

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 8:09am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/17 "2023-01-12T08:09:06Z")

</div>

Which file could I add this too?

````plaintext
    root "C:/WEB_SERVERS";
}```
````

---

<div class="post-metadata">

**Author:** ![RaffiMWRP](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@RaffiMWRP](https://community.letsencrypt.org/u/RaffiMWRP)\
**Post date:** [January 12, 2023, 8:15am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/18 "2023-01-12T08:15:54Z")

</div>

The one thing I would like to mention is that the previous admin did have this functioning and working. Since I have just taken over as Admin, no changes were done in regards to the configuration.

Thank you again for anyone who can help.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 8:17am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/19 "2023-01-12T08:17:30Z")

</div>

It probably wouldn't hurt to add such a section to all the server blocks that listen on port 80.  
But to address the three sites in question here, you can hit them all in this one file:

```plaintext
# configuration file C:\WEB_SERVERS\NGINX/conf/mwrp/midwestrp.net.conf:

server {
    listen 80;
    server_name midwestrp.net;
...
}

server {
    listen 80;
    server_name www.midwestrp.net;
...
}

server {
    listen 80;
    server_name ia.midwestrp.net;
...
}

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 12, 2023, 8:19am UTC](https://community.letsencrypt.org/t/invalid-response-errors/191037/20 "2023-01-12T08:19:25Z")

</div>

You could also make it simpler by using an `include` statement [to a file that contains the additional code].  
That way you can make corrects to that code on one single place [reducing possible typos].

[Next page](https://community.letsencrypt.org/t/invalid-response-errors/191037.md?page=2)
