limit_req_zone $http_x_forwarded_for zone=limite:10m rate=5r/s; server { listen 80; server_name _; root /var/www/html; index index.php index.html index.htm; location ~ /\. { deny all; access_log off; log_not_found off; } # Bloquear escaneos y path traversal location ~* (@fs|etc/passwd) { deny all; access_log off; } location / { try_files $uri $uri/ /index.php?$args; } location ~ \.php$ { include fastcgi_params; fastcgi_pass fpm:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param HTTP_X_FORWARDED_PROTO $http_x_forwarded_proto; fastcgi_param HTTPS 'on'; } }