部署到F5环境后Web Service出现404 Not Found错误的排查请求
排查WCF服务在F5环境下HTTPS绑定后的404问题
我来帮你拆解这个问题——核心矛盾是F5的请求转发逻辑和你新修改的WCF配置不匹配,导致服务找不到对应的处理端点。下面一步步分析并给出解决方案:
问题根源分析
先梳理你的场景:
- 原配置:仅HTTP端点,
security mode="TransportCredentialOnly"(适配HTTP上的Windows认证),F5把外部请求转成HTTP发到IIS 80端口,服务正常。 - 修改后:新增了HTTPS绑定和对应的
Transport模式binding,但默认的HTTP binding被改成了security mode="None",且服务仍然只绑定了一个未指定配置的默认端点。
当F5把请求转发为HTTP到80端口时,WCF找不到匹配TransportCredentialOnly模式的端点(你把默认binding的安全模式改了),直接返回404;而无F5的测试环境中,请求直接走HTTPS,匹配到了你新增的pt_httpsBinding,所以能正常工作。
解决方案:适配双协议的端点配置
你需要明确为HTTP和HTTPS分别配置对应的binding和端点,让两种请求都能找到正确的处理逻辑。修改后的<system.serviceModel>核心配置如下:
<system.serviceModel> <behaviors> <endpointBehaviors> <behavior name="trakWebclientServices.WebclientServiceAspNetAjaxBehavior"> <enableWebScript /> </behavior> </endpointBehaviors> </behaviors> <bindings> <webHttpBinding> <!-- 适配F5转发的HTTP请求,保留原有的Windows认证逻辑 --> <binding name="pt_httpBinding" maxReceivedMessageSize="2147483647"> <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" /> <security mode="TransportCredentialOnly"> <transport clientCredentialType="Windows" /> </security> </binding> <!-- 适配直接访问的HTTPS请求 --> <binding name="pt_httpsBinding" maxReceivedMessageSize="2147483647"> <readerQuotas maxDepth="2147483647" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647"/> <security mode="Transport"> <transport clientCredentialType="None"/> </security> </binding> </webHttpBinding> </bindings> <serviceHostingEnvironment aspNetCompatibilityEnabled="true" multipleSiteBindingsEnabled="true" /> <services> <service name="trakWebclientServices.WebclientService"> <!-- HTTP端点:对应F5转发的80端口请求 --> <endpoint address="" behaviorConfiguration="trakWebclientServices.WebclientServiceAspNetAjaxBehavior" binding="webHttpBinding" bindingConfiguration="pt_httpBinding" contract="trakWebclientServices.WebclientService" /> <!-- HTTPS端点:对应直接访问的HTTPS绑定请求 --> <endpoint address="" behaviorConfiguration="trakWebclientServices.WebclientServiceAspNetAjaxBehavior" binding="webHttpBinding" bindingConfiguration="pt_httpsBinding" contract="trakWebclientServices.WebclientService" /> </service> </services> </system.serviceModel>
额外检查项
- IIS配置验证:
- 确保站点同时开启HTTP(80)和HTTPS绑定,HTTPS绑定的证书有效。
- 站点认证设置:如果原服务依赖Windows认证,需开启IIS的Windows认证,并确保HTTPS绑定的认证规则符合你的业务需求(比如是否允许匿名)。
- F5配置验证:
- 确认F5是将外部请求正确转发到IIS的80端口,未修改请求路径或删除必要的请求头。
排查进阶:启用WCF跟踪日志
如果修改后仍有问题,可以开启WCF的跟踪日志,查看具体的错误细节:
在web.config的根节点下添加以下配置:
<system.diagnostics> <sources> <source name="System.ServiceModel" switchValue="Information, ActivityTracing" propagateActivity="true"> <listeners> <add name="traceListener" type="System.Diagnostics.XmlWriterTraceListener" initializeData="c:\logs\WcfTrace.svclog" /> </listeners> </source> </sources> </system.diagnostics>
重现错误后,用Visual Studio打开生成的WcfTrace.svclog文件,就能看到端点匹配失败、认证错误等具体原因。
内容的提问来源于stack exchange,提问作者drzounds
相关产品推荐
相关产品推荐

