You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAProxy配置咨询:基于源IP的ACL后端访问控制设置方法

问题描述

我当前的HAProxy frontend配置如下,想添加基于源IP的ACL规则实现特定后端的访问控制:

  • 仅允许10.10.0.0/16和10.5.0.0/16访问web主机(对应linux和windows的域名)
  • 允许所有IP(0.0.0.0/0)访问public主机

当前frontend配置:

frontend web
  bind :80
  bind :443 ssl crt /etc/ssl/certs/[redacted]/
  http-request redirect scheme https unless { ssl_fc }
  option http-server-close
  http-request set-header X-Forwarded-Proto https if { ssl_fc }
  use_backend %[req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map)]

示例/etc/haproxy/maps/hosts.map配置:

example1.com webhost-linux-servers
example2.com webhost-windows-servers
example3.com publichost-linux-servers
example4.com publichost-windows-servers
实现步骤

通过定义ACL规则和添加访问控制逻辑即可实现需求,具体修改如下:

1. 定义核心ACL规则

在frontend区块内新增以下ACL规则:

# 匹配允许访问web主机的源IP段
acl allowed_web_src src 10.10.0.0/16 10.5.0.0/16
# 匹配指向web主机的请求(通过host映射结果判断)
acl is_web_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str webhost-linux-servers webhost-windows-servers
# 匹配指向public主机的请求
acl is_public_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str publichost-linux-servers publichost-windows-servers

2. 添加访问控制逻辑

在use_backend指令之前,添加拒绝不符合条件请求的规则:

# 针对web主机的请求,仅允许指定IP段访问,其他IP直接拒绝
http-request deny if is_web_backend !allowed_web_src

3. 完整修改后的frontend配置

最终配置如下:

frontend web
  bind :80
  bind :443 ssl crt /etc/ssl/certs/[redacted]/
  http-request redirect scheme https unless { ssl_fc }
  option http-server-close
  http-request set-header X-Forwarded-Proto https if { ssl_fc }

  # 新增ACL规则
  acl allowed_web_src src 10.10.0.0/16 10.5.0.0/16
  acl is_web_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str webhost-linux-servers webhost-windows-servers
  acl is_public_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str publichost-linux-servers publichost-windows-servers

  # 访问控制逻辑
  http-request deny if is_web_backend !allowed_web_src

  # 原有后端映射规则
  use_backend %[req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map)]

规则说明

  • allowed_web_src:精准匹配来自10.10.0.0/16和10.5.0.0/16的请求源IP
  • is_web_backend:通过host域名的映射结果,判断当前请求是否指向web类后端
  • http-request deny if is_web_backend !allowed_web_src:当请求目标是web后端,但源IP不在允许列表时,直接拒绝该请求
  • public类后端未添加限制规则,默认所有IP均可正常访问

内容的提问来源于stack exchange,提问作者David Wruck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 07:47:09