You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache 2.4迁移后MaxMindDB/GeoIP国家流量封禁失效求助

Apache 2.4 MaxMindDB 国家流量封禁失效问题排查求助

近期将Apache服务器从2.2版本迁移至2.4版本,尝试通过MaxMindDB与GeoIP模块封禁特定国家的流量。先后测试旧版GeoIP模块配置、mod_maxminddb模块均未成功,已查阅模块文档、重启Apache服务,问题仍存在。

已执行操作步骤

  • 按官方文档在RHEL 9系统中安装httpd
  • 尝试通过yum安装mod_geoip2模块,安装失败
  • 转而使用已部署的maxminddb模块
  • 配置模块规则以封禁特定国家流量
  • 重启Apache服务

效果对比

预期效果:被封禁国家的流量无法访问网站
实际效果:被封禁国家的流量仍可正常访问网站

虚拟主机配置

<VirtualHost *:80>
ServerName URL
DocumentRoot "/var/www/html"
<Location />
    MaxMindDBEnable On
    SetEnvIf CLIENTIP "(.*)" MMDB_ADDR=$1
    MaxMindDBEnv CB_COUNTRY_CODE COUNTRY_DB/country/iso_code
    MaxMindDBEnv CB_COUNTRY_NAME COUNTRY_DB/country/names/en
    SetEnvIfExpr "env('CB_COUNTRY_CODE') =~ /^US$|^CA$|^IN$/i" match
    Header always set X-Country-Code_match "%{match}e"
    SetEnvIf CB_COUNTRY_CODE ^(US|CA|IN) AllowCountry
    Header always set MMDB_ADDR "%{MMDB_ADDR}e"
    Header always set CB_COUNTRY_CODE "%{CB_COUNTRY_CODE}e"
    Header always set X-Country-Allow "%{AllowCountry}e"

</Location>

SetEnvIf REMOTE_ADDR "(.+)" CLIENTIP=$1
SetEnvIf X-Forwarded-For "^([0-9.]+)" CLIENTIP=$1
ErrorLog /var/log/httpd/error_log-web1
CustomLog /var/log/httpd/access_log-web1 combined env=!forwarded
LogFormat "%{CLIENTIP}e %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" proxy
SetEnvIf X-Forwarded-For "^.*\..*\..*\..*" forwarded
CustomLog /var/log/httpd/URL.log proxy env=forwarded

LogFormat "%{CLIENTIP}e \"%{Referer}i\" %h %l %u %t \"%r\" %>s %b duration:%T/%D balancer:%{BALANCER_WORKER_NAME}e Changed:%{BALANCER_ROUTE_CHANGED}e Sticky:%{BALANCER_SESSION_STICKY}e" enhancedlog
SetEnvIf Request_URI "^/zkau$" tzkau
CustomLog  /var/log/httpd/enhancedlog.log-web1 enhancedlog env=tzkau

LogFormat "%{CLIENTIP}e \"%{Referer}i\" url:%U %h %l %u %t \"%r\" %>s %b clientip:%a duration:%T/%D balancer:%{BALANCER_WORKER_NAME}e sessionRoute:%{BALANCER_SESSION_ROUTE}e workerRoute:%{BALANCER_WORKER_ROUTE}e Changed:%{BALANCER_ROUTE_CHANGED}e Sticky:%{BALANCER_SESSION_STICKY}e"
TransferLog     /var/log/httpd/new-log-web1 

RewriteEngine on

Header always set Strict-Transport-Security "max-age=63072000"

RewriteCond %{REQUEST_URI} ^/Keyword/index\.zul
RewriteRule (.*) /index\.zul [L,R]
RewriteRule ^(.*)/Keyword/?(.*) $1/$2 [L,R]
RewriteRule ^(.*)/Keyword/ $1 [L,R]

RewriteCond %{REQUEST_URI} ^/bizclub [or]
RewriteCond %{REQUEST_URI} ^/bizbox
RewriteRule (.*) https://URL [L,R=301]

RewriteCond %{HTTP_USER_AGENT} "^ELB-HealthChecker" [NC,OR]
RewriteRule .* - [S=3]
RewriteCond %{HTTP_HOST} !^Keyword\.com [or]
RewriteCond %{HTTP:X-Forwarded-Proto} =http
RewriteRule (.*) https://URL$1 [L,R=301]
ProxyPreserveHost On
ProxyPass /index.html !
ProxyPass /favicon.ico !
ProxyErrorOverride on
ProxyPass /error !
ProxyPass /error/ !
ErrorDocument 500 /error/error.html
ErrorDocument 503 /error/error.html
ErrorDocument 404 /error/error.html

ProxyPass / balancer://wwwcluster/ stickysession=JSESSIONID|jsessionid scolonpathdelim=On
ProxyPassReverse / balancer://wwwcluster/
ProxyTimeout 60000
Header add Set-Cookie "ROUTEID=.%{BALANCER_WORKER_ROUTE}e; path=/\" env=BALANCER_ROUTE_CHANGED
<Proxy balancer://wwwcluster>
BalancerMember http://<IP>:8090 route=node1 keepalive=on
ProxySet lbmethod=bytraffic
ProxySet stickysession=ROUTEID
</Proxy>
</VirtualHost>

排查建议

1. 确认MMDB数据库加载状态

  • 检查httpd全局配置(如/etc/httpd/conf.d/maxminddb.conf)是否存在MaxMindDBFile COUNTRY_DB /path/to/GeoLite2-Country.mmdb配置,确保数据库路径正确、文件存在且权限允许httpd进程读取
  • 执行httpd -M | grep maxminddb确认mod_maxminddb模块已成功加载

2. 调整CLIENTIP变量的定义顺序

当前配置中SetEnvIf REMOTE_ADDR和SetEnvIf X-Forwarded-For位于<Location>块之后,导致<Location>内的MMDB_ADDR无法获取正确客户端IP。需将这两行移至<VirtualHost>开头、<Location>块之前:

<VirtualHost *:80>
ServerName URL
DocumentRoot "/var/www/html"
# 移至此处
SetEnvIf REMOTE_ADDR "(.+)" CLIENTIP=$1
SetEnvIf X-Forwarded-For "^([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)" CLIENTIP=$1

<Location />
    MaxMindDBEnable On
    SetEnvIf CLIENTIP "(.*)" MMDB_ADDR=$1
    # 其余配置保留
</Location>

3. 添加核心封禁规则

当前配置仅定义了AllowCountry变量,未实现实际封禁逻辑。在<Location>块中添加以下规则(Apache 2.4推荐用Require指令):

<Location />
    # 原有配置保留
    # 拒绝非允许国家的流量
    Require env AllowCountry
    # 若需兼容旧规则可使用:
    # Order Deny,Allow
    # Deny from all
    # Allow from env=AllowCountry
</Location>

4. 调试变量赋值正确性

  • 访问网站后查看响应头中的X-Country-Code、MMDB_ADDR字段,确认客户端IP与匹配的国家码是否正确
  • 查看/var/log/httpd/error_log-web1,搜索是否存在MaxMindDB相关错误(如数据库加载失败、路径错误)

5. 优化反向代理场景的IP获取

若前端有ELB等反向代理,X-Forwarded-For可能包含多个IP,建议启用mod_remoteip模块并配置:

LoadModule remoteip_module modules/mod_remoteip.so
RemoteIPHeader X-Forwarded-For
RemoteIPInternalProxy <ELB-IP>

通过该模块可更可靠地获取客户端真实IP,替代手动设置CLIENTIP的方式

内容的提问来源于stack exchange,提问作者Rushit Chandegara

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 01:17:03