HAProxy配置咨询:基于源IP的ACL后端访问控制设置方法
问题描述
我当前的HAProxy frontend配置如下,想添加基于源IP的ACL规则实现特定后端的访问控制:
- 仅允许
10.10.0.0/16和10.5.0.0/16访问web主机(对应linux和windows的域名) - 允许所有IP(
0.0.0.0/0)访问public主机
当前frontend配置:
frontend web bind :80 bind :443 ssl crt /etc/ssl/certs/[redacted]/ http-request redirect scheme https unless { ssl_fc } option http-server-close http-request set-header X-Forwarded-Proto https if { ssl_fc } use_backend %[req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map)]
示例/etc/haproxy/maps/hosts.map配置:
example1.com webhost-linux-servers example2.com webhost-windows-servers example3.com publichost-linux-servers example4.com publichost-windows-servers
实现步骤
通过定义ACL规则和添加访问控制逻辑即可实现需求,具体修改如下:
1. 定义核心ACL规则
在frontend区块内新增以下ACL规则:
# 匹配允许访问web主机的源IP段 acl allowed_web_src src 10.10.0.0/16 10.5.0.0/16 # 匹配指向web主机的请求(通过host映射结果判断) acl is_web_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str webhost-linux-servers webhost-windows-servers # 匹配指向public主机的请求 acl is_public_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str publichost-linux-servers publichost-windows-servers
2. 添加访问控制逻辑
在use_backend指令之前,添加拒绝不符合条件请求的规则:
# 针对web主机的请求,仅允许指定IP段访问,其他IP直接拒绝 http-request deny if is_web_backend !allowed_web_src
3. 完整修改后的frontend配置
最终配置如下:
frontend web bind :80 bind :443 ssl crt /etc/ssl/certs/[redacted]/ http-request redirect scheme https unless { ssl_fc } option http-server-close http-request set-header X-Forwarded-Proto https if { ssl_fc } # 新增ACL规则 acl allowed_web_src src 10.10.0.0/16 10.5.0.0/16 acl is_web_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str webhost-linux-servers webhost-windows-servers acl is_public_backend req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map) -m str publichost-linux-servers publichost-windows-servers # 访问控制逻辑 http-request deny if is_web_backend !allowed_web_src # 原有后端映射规则 use_backend %[req.hdr(host),lower,map_dom(/etc/haproxy/maps/hosts.map)]
规则说明
allowed_web_src:精准匹配来自10.10.0.0/16和10.5.0.0/16的请求源IPis_web_backend:通过host域名的映射结果,判断当前请求是否指向web类后端http-request deny if is_web_backend !allowed_web_src:当请求目标是web后端,但源IP不在允许列表时,直接拒绝该请求- public类后端未添加限制规则,默认所有IP均可正常访问
内容的提问来源于stack exchange,提问作者David Wruck
相关产品推荐
相关产品推荐

