生产环境IIS因单URL请求过载宕机,能否对该URL限流及如何操作?
可以在IIS中针对单个URL限流,以下是两种可行的临时方案
方案一:使用URL Rewrite + ARR(Application Request Routing)实现单URL限流
ARR是微软官方的IIS扩展,可结合URL Rewrite针对特定URL设置请求速率限制,无需修改业务代码。
前置准备
确保服务器已安装URL Rewrite和ARR模块:
- 打开服务器管理器 → 添加角色和功能 → 在Web服务器(IIS)的角色服务中,勾选URL Rewrite和Application Request Routing,完成安装后重启IIS。
配置步骤
- 打开IIS管理器,选中目标站点,进入Application Request Routing Cache模块。
- 在右侧操作栏点击Server Proxy Settings,勾选Enable proxy(ARR需开启代理模式才能启用限流功能),点击确定。
- 返回站点,进入URL Rewrite模块,点击右侧Add Rule(s)。
- 选择Blank Rule,配置规则:
- Match URL:
- Requested URL:
Matches the Pattern - Using:
Regular Expressions - Pattern: 填写要限流的URL路径,例如
^/api/high-traffic-endpoint$(根据实际URL调整,正则需准确匹配目标路径) - 勾选Ignore case
- Requested URL:
- Conditions:可按需添加(比如仅限制POST请求,可添加条件
{REQUEST_METHOD}匹配^POST$) - Action:
- Action Type:
Rewrite - Rewrite URL:
http://localhost{REQUEST_URI}(将请求转发回本地,触发ARR的限流逻辑) - 勾选Append query string
- Action Type:
- Match URL:
- 配置ARR限流阈值:
- 回到站点,进入Application Request Routing Cache → 点击右侧Request Limits。
- 在Rate Limiting区域,勾选Enable rate limiting,设置:
- Maximum requests per second: 输入服务器能承受的该URL每秒请求数(例如100)
- Maximum concurrent requests: 输入该URL允许的并发请求数(例如50)
- 点击Apply,重启站点使配置生效。
注:该规则会作用于所有匹配目标URL的请求,若需更精细控制(如排除特定用户代理),可在URL Rewrite的Conditions中添加额外过滤条件。
方案二:使用自定义HTTP模块(仅适用于.NET应用)
如果是ASP.NET应用,可快速编写轻量HTTP模块实现单URL限流,无需安装额外IIS扩展。
示例代码(C#)
public class UrlRateLimitModule : IHttpModule { private static readonly Dictionary<string, Queue<DateTime>> _requestLogs = new Dictionary<string, Queue<DateTime>>(); private const int MaxRequestsPerMinute = 100; private const string TargetUrl = "/api/high-traffic-endpoint"; // 替换为目标URL public void Init(HttpApplication context) { context.BeginRequest += Context_BeginRequest; } private void Context_BeginRequest(object sender, EventArgs e) { var app = (HttpApplication)sender; var requestUrl = app.Context.Request.Url.AbsolutePath; if (!requestUrl.Equals(TargetUrl, StringComparison.OrdinalIgnoreCase)) return; lock (_requestLogs) { if (!_requestLogs.ContainsKey(TargetUrl)) _requestLogs[TargetUrl] = new Queue<DateTime>(); var log = _requestLogs[TargetUrl]; var now = DateTime.Now; // 清除1分钟前的请求记录 while (log.Count > 0 && now.Subtract(log.Peek()).TotalMinutes > 1) log.Dequeue(); if (log.Count >= MaxRequestsPerMinute) { app.Context.Response.StatusCode = 429; app.Context.Response.StatusDescription = "Too Many Requests"; app.Context.Response.End(); return; } log.Enqueue(now); } } public void Dispose() { } }
配置步骤
- 将上述代码编译为DLL,放入应用的
bin目录。 - 在应用的
web.config中注册模块:
<system.webServer> <modules> <add name="UrlRateLimitModule" type="YourNamespace.UrlRateLimitModule, YourAssemblyName" /> </modules> </system.webServer>
- 重启应用池,规则即可生效。
注意事项
- 方案一为服务器层面限流,支持所有IIS托管的应用类型(静态页面、PHP、.NET等);方案二仅适用于.NET应用。
- 限流阈值需根据服务器性能和业务实际需求调整,建议先在测试环境验证后再上线。
- 应用永久修复完成后,记得移除对应的限流规则或模块,避免影响正常业务访问。
内容的提问来源于stack exchange,提问作者Jammy
相关产品推荐
相关产品推荐

