Nginx只允许域名访问,禁止IP访问

QuibblerQuibbler 2020-08-13 约 9 分钟 1714 次阅读

Nginx只允许域名访问,禁止IP访问

IP地址很容易暴露,通过域名访问则相对安全,而且不管换到哪台服务器上,只需要通过域名访问就行了。不希望自己的站点通过IP(114.116.128.229)被访问,只允许通过唯一域名Quibbler.cn访问。那么该如何设置呢?


1、Nginx配置

nginx配置文件是/usr/local/nginx/conf目录下的nginx.conf文件。修改server节点中部分字段:

...
        server_name quibbler.cn;
        if ($host != 'quibbler.cn'){
  			return 403;
		}
    ...

修改后的完整conf配置文件

user  www www;
worker_processes auto;
worker_cpu_affinity auto;
error_log  /home/wwwlogs/nginx_error.log  crit;
pid        /usr/local/nginx/logs/nginx.pid;
#Specifies the value for maximum file descriptors that can be opened by this process.
worker_rlimit_nofile 51200;
events
    {
        use epoll;
        worker_connections 51200;
        multi_accept off;
        accept_mutex off;
    }
http
    {
        include       mime.types;
        default_type  application/octet-stream;
        server_names_hash_bucket_size 128;
        client_header_buffer_size 32k;
        large_client_header_buffers 4 32k;
        client_max_body_size 50m;
        sendfile on;
        sendfile_max_chunk 512k;
        tcp_nopush on;
        keepalive_timeout 60;
        tcp_nodelay on;
        fastcgi_connect_timeout 300;
        fastcgi_send_timeout 300;
        fastcgi_read_timeout 300;
        fastcgi_buffer_size 64k;
        fastcgi_buffers 4 64k;
        fastcgi_busy_buffers_size 128k;
        fastcgi_temp_file_write_size 256k;
        gzip on;
        gzip_min_length  1k;
        gzip_buffers     4 16k;
        gzip_http_version 1.1;
        gzip_comp_level 2;
        gzip_types     text/plain application/javascript application/x-javascript;
        gzip_vary on;
        gzip_proxied   expired no-cache no-store private auth;
        gzip_disable   "MSIE [1-6]\.";
        #limit_conn_zone $binary_remote_addr zone=perip:10m;
        ##If enable limit_conn_zone,add "limit_conn perip 10;" to server section.
        server_tokens off;
        access_log off;
server
    {
        listen 80 default_server reuseport;
        #listen [::]:80 default_server ipv6only=on;
        server_name quibbler.cn;
        if ($host != 'quibbler.cn'){
  			return 403;
		}
        index index.html index.htm index.php;
        root  /home/wwwroot/default;
        #error_page   404   /404.html;
        # Deny access to PHP files in specific directory
        #location ~ /(wp-content|uploads|wp-includes|images)/.*\.php$ { deny all; }
        include enable-php.conf;
        location /nginx_status
        {
            stub_status on;
            access_log   off;
        }
        location ~ .*\.(gif|jpg|jpeg|png|bmp|swf)$
        {
            expires      30d;
        }
        location ~ .*\.(js|css)?$
        {
            expires      12h;
        }
        location ~ /.well-known {
            allow all;
        }
        location ~ /\.
        {
            deny all;
        }
        access_log  /home/wwwlogs/access.log;
    }
include vhost/*.conf;
}

2、重启Nginx

进入到nginx可执行文件目录。

cd /usr/local/nginx/sbin

重启nginx服务,让修改的配置生效。

./nginx -s reload

这样就只允许通过域名访问。

参考资料:

        nginx只允许域名访问,禁止ip访问

        nginx禁止IP只允许域名访问

        让apache只允许域名访问而禁止IP实现方法

        nginx只允许域名访问,禁止ip访问

        linux下apache配置文件在哪里

相关推荐

精选
国内开源镜像站点
分享

国内开源镜像站点

国内开源镜像站点开源,(Open Source)全称为开放源代码。开源就是要用户利用源代码在其基础上修改和学习的,但开源系统同样也有版权,同样也受到法律保护。国内的高校和一些企业也建立了开源镜像站点,支持开源。从开源站点上面可以下载很多开源资源(Android源码),上大学的时候就在这些镜像网站上下载Linux发行版、Qt等软件。 清华大学:http://mirrors.tuna.tsinghua

2.4k
R8编译问题:Missing classes detected while running R8
分享

R8编译问题:Missing classes detected while running R8

R8编译问题:Missing classes detected while running R8Android R8是一个代码混淆和压缩工具,可以将应用程序的大小和安全性优化。它引入了一些新功能,如成员内省、混淆指针、类内省等。但R8使用起来一直不友好,因为自从使用R8之后编译问题不断。主要还是和混淆相关,经常报错,最近又遇到一个:Missing classes detected while ru

8.4k
maven { url 'https://jitpack.io' } 无法下载的问题
分享

maven { url 'https://jitpack.io' } 无法下载的问题

解决maven { url 'https://jitpack.io' } 无法下载的问题要使用GitHub上项目的开源库,比如 BRV ,加强版的RecyclerView框架:需要在项目根目录的 build.gradle 添加 jitpack 仓库:以上这些都照做了,却遇到Gradle无法下载依赖的问题。这种情况以前也遇到过,一般是由于网络故障引起的,可以用国内的镜像仓库。尝试了不同方法,仍然无法

6.6k