nginx°×Ãûµ¥ÔõôÉèÖÃ
nginx °×Ãûµ¥ÏÞÖÆ»á¼ûÌض¨ÄÚÈÝ£¬½öÔÊÐíÀ´×ÔÊÚȨȪԴµÄÇëÇó¡£ÉèÖð취ÈçÏ£ºÈ·¶¨ÔÊÐíµÄ ip µØµã»òÓòÃû¡£½¨Éè nginx ЧÀÍÆ÷¿éÀ´´¦Öóͷ£ÇëÇó¡£Ìí¼Ó allow Ö¸ÁÔÊÐíÖ¸¶¨ÈªÔ´»á¼û¡£Ìí¼Ó deny Ö¸Á¿ÉÑ¡£©£¬¾Ü¾ø³ý°×Ãûµ¥ÍâµÄËùÓлá¼û¡£ÉúÑÄÉèÖò¢ÖØмÓÔØ nginx¡£
ÔõÑùÉèÖà nginx °×Ãûµ¥
ÔÚ nginx ÖУ¬°×Ãûµ¥ÊÇÒ»ÖÖ»á¼û¿ØÖÆ»úÖÆ£¬ÓÃÓÚÏÞÖƶÔÍøÕ¾»òÓ¦ÓóÌÐòÌض¨²¿·ÖµÄ»á¼û£¬½öÔÊÐíÀ´×ÔÊÚȨȪԴµÄÇëÇó¡£ÒÔÏ°취˵Ã÷ÎúÔõÑùÉèÖà nginx °×Ãûµ¥£º
1. È·¶¨ÔÊÐíµÄ IP µØµã»òÓòÃû
Ê×ÏÈ£¬È·¶¨ÒªÔÊÐí»á¼ûÊܱ£»¤ÄÚÈÝµÄ IP µØµã»òÓòÃû¡£ÕâЩ¿ÉÄÜÊÇÄã×Ô¼ºµÄ IP µØµã¡¢ÊÜÐÅÍеÄÏàÖúͬ°é»ò¿Í»§µÄ IP µØµã¡£
2. ½¨Éè nginx ÉèÖÿé
ÔÚ nginx ÉèÖÃÎļþÖУ¬½¨ÉèÒ»¸öеÄЧÀÍÆ÷¿éÀ´´¦Öóͷ£½«Ó¦Óð×Ãûµ¥µÄÇëÇó¡£
3. Ìí¼Ó allow Ö¸Áî
ÔÚЧÀÍÆ÷¿éÖУ¬Ìí¼ÓÒÔÏ allow Ö¸ÁÒÔÔÊÐíÀ´×ÔÖ¸¶¨ IP µØµã»òÓòÃûµÄ»á¼û£º
allow 192.168.0.1; allow example.com;
µÇ¼ºó¸´ÖÆ
4. Ìí¼Ó deny Ö¸Á¿ÉÑ¡£©
ÈôÊÇÄãÏ£Íû¾Ü¾ø³ý°×Ãûµ¥ÒÔÍâµÄËùÓлá¼û£¬Ôò¿ÉÒÔÌí¼Ó deny Ö¸Á
deny all;
µÇ¼ºó¸´ÖÆ
5. ÉúÑÄÉèÖò¢ÖØмÓÔØ nginx
ÉúÑÄ nginx ÉèÖÃÎļþ²¢½«¸ü¸ÄÓ¦ÓÃÓÚЧÀÍÆ÷£º
sudo systemctl reload nginx
µÇ¼ºó¸´ÖÆ
ʾÀýÉèÖÃ
ÒÔÏÂÊÇ nginx °×Ãûµ¥ÉèÖÃʾÀý£º
server { listen 80; location /protected/ { allow 192.168.0.1; allow example.com; deny all; } }
µÇ¼ºó¸´ÖÆ
´ËÉèÖý«ÔÊÐíÀ´×Ô 192.168.0.1 IP µØµãºÍ example.com ÓòÃûµÄÇëÇó»á¼û /protected/ Ŀ¼£¬¶ø¾Ü¾øËùÓÐÆäËûÇëÇó¡£
ÒÔÉϾÍÊÇnginx°×Ãûµ¥ÔõôÉèÖõÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡