You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中配置Azure应用网关IP白名单?

在Azure应用网关(WAF_v2)中通过Terraform设置IP白名单

你可以通过在应用网关的waf_configuration块中添加自定义规则来实现IP白名单限制,以下是修改后的完整配置示例:

resource "azurerm_application_gateway" "app_gateway" {
    name                = "agw-${local.application_context}"
    resource_group_name = data.azurerm_resource_group.resource_group.name
    location            = data.azurerm_resource_group.resource_group.location
    ...

    sku {
     name     = "WAF_v2"
     tier     = "WAF_v2"
     capacity = 2
   }

   gateway_ip_configuration {
        name      = "agw-${local.application_context}"
        subnet_id = azurerm_subnet.snet.id
   }

   frontend_port {
     ....
   }
 
 .....

 waf_configuration {
   enabled                  = true
   firewall_mode            = "Prevention"
   rule_set_type            = "OWASP"
   rule_set_version         = "3.2"
   file_upload_limit_mb     = 100
   max_request_body_size_kb = 128
   request_body_check       = false

   # 核心:IP白名单允许规则
   custom_rules {
     name      = "AllowTrustedIPs"
     priority  = 1 # 优先级最高,确保先执行
     rule_type = "MatchRule"
     action    = "Allow"

     match_conditions {
       match_variables {
         variable_name = "RemoteAddr" # 匹配客户端源IP
       }

       operator           = "IPMatch"
       match_values       = ["192.168.1.0/24", "10.0.0.5"] # 替换为你的目标IP/网段
       negation_condition = false
     }
   }

   # 可选:严格拒绝所有非白名单IP(按需添加)
   custom_rules {
     name      = "DenyAllNonTrustedIPs"
     priority  = 2 # 优先级低于白名单规则
     rule_type = "MatchRule"
     action    = "Deny"

     match_conditions {
       match_variables {
         variable_name = "RemoteAddr"
       }

       operator           = "IPMatch"
       match_values       = ["0.0.0.0/0"] # 匹配所有IP
       negation_condition = true # 取反,即匹配不在白名单内的IP
     }
   }
 }
}

关键配置说明:

  • 优先级(priority):数值越小优先级越高,允许规则必须比拒绝规则优先级高,确保符合白名单的请求直接被放行,不会触发后续拒绝逻辑。
  • 匹配变量(RemoteAddr):指定匹配客户端的源IP地址,是实现IP白名单的核心变量。
  • 匹配值(match_values):填入需要允许的单个IP或者CIDR格式的网段,多个值用逗号分隔。
  • 可选拒绝规则:如果需要严格限制仅白名单IP可访问,添加第二条规则,通过negation_condition = true匹配所有不在白名单内的IP并拒绝。

注意:保持firewall_mode = "Prevention"会直接拦截不符合规则的请求;如果仅需测试日志,可改为Detection模式。

内容的提问来源于stack exchange,提问作者Fabry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 20:12:40