Apache 2.4迁移后MaxMindDB/GeoIP国家流量封禁失效求助
Apache 2.4 MaxMindDB 国家流量封禁失效问题排查求助
近期将Apache服务器从2.2版本迁移至2.4版本,尝试通过MaxMindDB与GeoIP模块封禁特定国家的流量。先后测试旧版GeoIP模块配置、mod_maxminddb模块均未成功,已查阅模块文档、重启Apache服务,问题仍存在。
已执行操作步骤
- 按官方文档在RHEL 9系统中安装httpd
- 尝试通过yum安装mod_geoip2模块,安装失败
- 转而使用已部署的maxminddb模块
- 配置模块规则以封禁特定国家流量
- 重启Apache服务
效果对比
预期效果:被封禁国家的流量无法访问网站
实际效果:被封禁国家的流量仍可正常访问网站
虚拟主机配置
<VirtualHost *:80> ServerName URL DocumentRoot "/var/www/html" <Location /> MaxMindDBEnable On SetEnvIf CLIENTIP "(.*)" MMDB_ADDR=$1 MaxMindDBEnv CB_COUNTRY_CODE COUNTRY_DB/country/iso_code MaxMindDBEnv CB_COUNTRY_NAME COUNTRY_DB/country/names/en SetEnvIfExpr "env('CB_COUNTRY_CODE') =~ /^US$|^CA$|^IN$/i" match Header always set X-Country-Code_match "%{match}e" SetEnvIf CB_COUNTRY_CODE ^(US|CA|IN) AllowCountry Header always set MMDB_ADDR "%{MMDB_ADDR}e" Header always set CB_COUNTRY_CODE "%{CB_COUNTRY_CODE}e" Header always set X-Country-Allow "%{AllowCountry}e" </Location> SetEnvIf REMOTE_ADDR "(.+)" CLIENTIP=$1 SetEnvIf X-Forwarded-For "^([0-9.]+)" CLIENTIP=$1 ErrorLog /var/log/httpd/error_log-web1 CustomLog /var/log/httpd/access_log-web1 combined env=!forwarded LogFormat "%{CLIENTIP}e %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" proxy SetEnvIf X-Forwarded-For "^.*\..*\..*\..*" forwarded CustomLog /var/log/httpd/URL.log proxy env=forwarded LogFormat "%{CLIENTIP}e \"%{Referer}i\" %h %l %u %t \"%r\" %>s %b duration:%T/%D balancer:%{BALANCER_WORKER_NAME}e Changed:%{BALANCER_ROUTE_CHANGED}e Sticky:%{BALANCER_SESSION_STICKY}e" enhancedlog SetEnvIf Request_URI "^/zkau$" tzkau CustomLog /var/log/httpd/enhancedlog.log-web1 enhancedlog env=tzkau LogFormat "%{CLIENTIP}e \"%{Referer}i\" url:%U %h %l %u %t \"%r\" %>s %b clientip:%a duration:%T/%D balancer:%{BALANCER_WORKER_NAME}e sessionRoute:%{BALANCER_SESSION_ROUTE}e workerRoute:%{BALANCER_WORKER_ROUTE}e Changed:%{BALANCER_ROUTE_CHANGED}e Sticky:%{BALANCER_SESSION_STICKY}e" TransferLog /var/log/httpd/new-log-web1 RewriteEngine on Header always set Strict-Transport-Security "max-age=63072000" RewriteCond %{REQUEST_URI} ^/Keyword/index\.zul RewriteRule (.*) /index\.zul [L,R] RewriteRule ^(.*)/Keyword/?(.*) $1/$2 [L,R] RewriteRule ^(.*)/Keyword/ $1 [L,R] RewriteCond %{REQUEST_URI} ^/bizclub [or] RewriteCond %{REQUEST_URI} ^/bizbox RewriteRule (.*) https://URL [L,R=301] RewriteCond %{HTTP_USER_AGENT} "^ELB-HealthChecker" [NC,OR] RewriteRule .* - [S=3] RewriteCond %{HTTP_HOST} !^Keyword\.com [or] RewriteCond %{HTTP:X-Forwarded-Proto} =http RewriteRule (.*) https://URL$1 [L,R=301] ProxyPreserveHost On ProxyPass /index.html ! ProxyPass /favicon.ico ! ProxyErrorOverride on ProxyPass /error ! ProxyPass /error/ ! ErrorDocument 500 /error/error.html ErrorDocument 503 /error/error.html ErrorDocument 404 /error/error.html ProxyPass / balancer://wwwcluster/ stickysession=JSESSIONID|jsessionid scolonpathdelim=On ProxyPassReverse / balancer://wwwcluster/ ProxyTimeout 60000 Header add Set-Cookie "ROUTEID=.%{BALANCER_WORKER_ROUTE}e; path=/\" env=BALANCER_ROUTE_CHANGED <Proxy balancer://wwwcluster> BalancerMember http://<IP>:8090 route=node1 keepalive=on ProxySet lbmethod=bytraffic ProxySet stickysession=ROUTEID </Proxy> </VirtualHost>
排查建议
1. 确认MMDB数据库加载状态
- 检查httpd全局配置(如
/etc/httpd/conf.d/maxminddb.conf)是否存在MaxMindDBFile COUNTRY_DB /path/to/GeoLite2-Country.mmdb配置,确保数据库路径正确、文件存在且权限允许httpd进程读取 - 执行
httpd -M | grep maxminddb确认mod_maxminddb模块已成功加载
2. 调整CLIENTIP变量的定义顺序
当前配置中SetEnvIf REMOTE_ADDR和SetEnvIf X-Forwarded-For位于<Location>块之后,导致<Location>内的MMDB_ADDR无法获取正确客户端IP。需将这两行移至<VirtualHost>开头、<Location>块之前:
<VirtualHost *:80> ServerName URL DocumentRoot "/var/www/html" # 移至此处 SetEnvIf REMOTE_ADDR "(.+)" CLIENTIP=$1 SetEnvIf X-Forwarded-For "^([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)" CLIENTIP=$1 <Location /> MaxMindDBEnable On SetEnvIf CLIENTIP "(.*)" MMDB_ADDR=$1 # 其余配置保留 </Location>
3. 添加核心封禁规则
当前配置仅定义了AllowCountry变量,未实现实际封禁逻辑。在<Location>块中添加以下规则(Apache 2.4推荐用Require指令):
<Location /> # 原有配置保留 # 拒绝非允许国家的流量 Require env AllowCountry # 若需兼容旧规则可使用: # Order Deny,Allow # Deny from all # Allow from env=AllowCountry </Location>
4. 调试变量赋值正确性
- 访问网站后查看响应头中的
X-Country-Code、MMDB_ADDR字段,确认客户端IP与匹配的国家码是否正确 - 查看
/var/log/httpd/error_log-web1,搜索是否存在MaxMindDB相关错误(如数据库加载失败、路径错误)
5. 优化反向代理场景的IP获取
若前端有ELB等反向代理,X-Forwarded-For可能包含多个IP,建议启用mod_remoteip模块并配置:
LoadModule remoteip_module modules/mod_remoteip.so RemoteIPHeader X-Forwarded-For RemoteIPInternalProxy <ELB-IP>
通过该模块可更可靠地获取客户端真实IP,替代手动设置CLIENTIP的方式
内容的提问来源于stack exchange,提问作者Rushit Chandegara
相关产品推荐
相关产品推荐

