You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在IIS重写/反向代理中允许携带utm_source、utm_medium参数

IIS反向代理携带utm_source/utm_medium参数访问报错问题

问题描述

我在Windows Server 2016和IIS中搭建了反向代理,整体运行正常,仅存在以下异常:

  • 无法正常访问格式为https://mywebsite/shop/product/3231?utm_source=IGShopping&utm_medium=Social的URL
  • 将URL中的utm_source修改为utm_sour等其他字符时,访问恢复正常
  • 直接通过localhost访问上述带utm参数的URL可正常打开
  • 仅当URL携带utm_source和utm_medium参数时才会触发报错

现有配置参考

web.config配置内容如下:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
    <system.webServer>
        <rewrite>
            <outboundRules>
                <clear />
                <rule name="Add SameSite" preCondition="No SameSite">
                    <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" />
                    <action type="Rewrite" value="{R:0}; SameSite=None; Secure" />
                </rule>
                <rule name="ReverseProxyOutboundRule1" preCondition="ResponseIsHtml1" enabled="true">
                    <match filterByTags="A, Form, Img" pattern="^http(s)?://localhost:8068/(.*)" />
                    <action type="Rewrite" value="http{R:1}://mocauae.ae/{R:2}" />
                </rule>
                <preConditions>
                    <preCondition name="ResponseIsHtml1">
                        <add input="{RESPONSE_CONTENT_TYPE}" pattern="^text/html" />
                    </preCondition>
                    <preCondition name="No SameSite">
                        <add input="{RESPONSE_Set_Cookie}" pattern="." />
                        <add input="{RESPONSE_Set_Cookie}" pattern="; SameSite=None; Secure" negate="true" />
                    </preCondition>
                </preConditions>
            </outboundRules>
            <rules>
                <rule name="ReverseProxyInboundRule1" enabled="true" stopProcessing="true">
                    <match url="(.*)" />
                    <action type="Rewrite" url="http://localhost:8068/{R:1}" />
                </rule>
                <rule name="HTTPS" enabled="false" patternSyntax="Wildcard" stopProcessing="true">
                    <match url="*" />
                    <conditions>
                        <add input="{HTTPS}" pattern="off" />
                    </conditions>
                    <action type="Redirect" url="http://localhost:8068" redirectType="Found" />
                </rule>
                <rule name="HTTPS force" enabled="false" stopProcessing="true">
                    <match url="(.*)" />
                    <conditions>
                        <add input="{HTTPS}" pattern="^OFF$" />
                    </conditions>
                    <action type="Redirect" url="https://localhost:8068" appendQueryString="false" redirectType="Permanent" />
                </rule>
                <rule name="https pure" enabled="false" patternSyntax="Wildcard" stopProcessing="true">
                    <match url="*" />
                    <action type="Redirect" url="https://localhost:8068" redirectType="Found" />
                    <conditions>
                        <add input="{HTTP}" pattern="off" />
                    </conditions>
                </rule>
            </rules>
        </rewrite>
        <httpRedirect enabled="false" destination="http://localhost:8068" exactDestination="true" />
    </system.webServer>
</configuration>

修复方案

问题根因

当前问题由两个配置缺陷共同导致:

  1. 入站反向代理规则未显式开启查询字符串透传,特殊参数传递出现截断
  2. IIS默认请求过滤规则拦截了utm_*开头的营销类查询参数,请求在到达重写规则前就被拒绝

操作步骤

  1. 修改反向代理入站规则,开启参数透传
    找到ReverseProxyInboundRule1规则,添加appendQueryString="true"属性:
<rule name="ReverseProxyInboundRule1" enabled="true" stopProcessing="true">
    <match url="(.*)" />
    <action type="Rewrite" url="http://localhost:8068/{R:1}" appendQueryString="true" />
</rule>
  1. 放行utm系列查询参数
    在web.config的<system.webServer>节点下新增如下配置,跳过请求过滤对utm参数的拦截:
<security>
    <requestFiltering>
        <alwaysAllowedQueryStrings>
            <add queryString="utm_source" />
            <add queryString="utm_medium" />
            <add queryString="utm_campaign" />
            <add queryString="utm_term" />
            <add queryString="utm_content" />
        </alwaysAllowedQueryStrings>
    </requestFiltering>
</security>
  1. 保存配置后重启IIS站点,重新测试带utm参数的链接即可正常访问。

内容的提问来源于stack exchange,提问作者Rana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 09:45:06