如何在Terraform中配置Azure应用网关IP白名单?
在Azure应用网关(WAF_v2)中通过Terraform设置IP白名单
你可以通过在应用网关的waf_configuration块中添加自定义规则来实现IP白名单限制,以下是修改后的完整配置示例:
resource "azurerm_application_gateway" "app_gateway" { name = "agw-${local.application_context}" resource_group_name = data.azurerm_resource_group.resource_group.name location = data.azurerm_resource_group.resource_group.location ... sku { name = "WAF_v2" tier = "WAF_v2" capacity = 2 } gateway_ip_configuration { name = "agw-${local.application_context}" subnet_id = azurerm_subnet.snet.id } frontend_port { .... } ..... waf_configuration { enabled = true firewall_mode = "Prevention" rule_set_type = "OWASP" rule_set_version = "3.2" file_upload_limit_mb = 100 max_request_body_size_kb = 128 request_body_check = false # 核心:IP白名单允许规则 custom_rules { name = "AllowTrustedIPs" priority = 1 # 优先级最高,确保先执行 rule_type = "MatchRule" action = "Allow" match_conditions { match_variables { variable_name = "RemoteAddr" # 匹配客户端源IP } operator = "IPMatch" match_values = ["192.168.1.0/24", "10.0.0.5"] # 替换为你的目标IP/网段 negation_condition = false } } # 可选:严格拒绝所有非白名单IP(按需添加) custom_rules { name = "DenyAllNonTrustedIPs" priority = 2 # 优先级低于白名单规则 rule_type = "MatchRule" action = "Deny" match_conditions { match_variables { variable_name = "RemoteAddr" } operator = "IPMatch" match_values = ["0.0.0.0/0"] # 匹配所有IP negation_condition = true # 取反,即匹配不在白名单内的IP } } } }
关键配置说明:
- 优先级(priority):数值越小优先级越高,允许规则必须比拒绝规则优先级高,确保符合白名单的请求直接被放行,不会触发后续拒绝逻辑。
- 匹配变量(RemoteAddr):指定匹配客户端的源IP地址,是实现IP白名单的核心变量。
- 匹配值(match_values):填入需要允许的单个IP或者CIDR格式的网段,多个值用逗号分隔。
- 可选拒绝规则:如果需要严格限制仅白名单IP可访问,添加第二条规则,通过
negation_condition = true匹配所有不在白名单内的IP并拒绝。
注意:保持firewall_mode = "Prevention"会直接拦截不符合规则的请求;如果仅需测试日志,可改为Detection模式。
内容的提问来源于stack exchange,提问作者Fabry
相关产品推荐
相关产品推荐

