You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何阻止使用服务器IP而非域名访问Nginx站点的请求?

How to Block Direct IP Access to Your Nginx Server

Got it, let's tackle this problem head-on. Blocking requests that use your server's IP address instead of your domain is a smart move to cut down on suspicious traffic and reduce your attack surface. Here are the most reliable methods to implement this:

1. Use a Default Server Block to Reject IP Requests

Nginx routes requests to the first matching server block, or a designated "default" one if no domain match is found. We can create a dedicated default block to immediately drop any IP-based requests.

Add this configuration to your Nginx setup (either in /etc/nginx/nginx.conf or a separate file in /etc/nginx/conf.d/):

server {
    listen 80 default_server;
    listen [::]:80 default_server;
    listen 443 ssl default_server;
    listen [::]:443 ssl default_server;

    # For SSL, use a self-signed cert if you don't have a domain-specific one here
    ssl_certificate /path/to/self-signed.crt;
    ssl_certificate_key /path/to/self-signed.key;

    server_name _; # Catches any server name (including raw IPs)

    # Return 444: Nginx-specific code that closes the connection without a response
    return 444;
    # Alternatively, send a 403 Forbidden if you want to explicitly deny access:
    # return 403;
}
  • return 444 is ideal because it gives attackers no feedback about your server, making probing harder.
  • To generate a self-signed SSL cert, run this command: openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /path/to/self-signed.key -out /path/to/self-signed.crt

2. Enforce Host Header Matching in Your Main Server Blocks

If you want to double down and ensure only requests with your valid domain in the Host header get through, add this check inside your existing domain-specific server blocks:

server {
    listen 80;
    listen [::]:80;
    listen 443 ssl;
    listen [::]:443 ssl;

    server_name yourdomain.com www.yourdomain.com;

    # Block any request where the Host header doesn't match your domain
    if ($host !~* ^(yourdomain.com|www.yourdomain.com)$) {
        return 444;
    }

    # Rest of your server configuration (root, index, location blocks, etc.)
    root /var/www/yourdomain;
    index index.html;
}

This catches any sneaky requests that might use your IP but spoof a non-matching Host header.

3. Test and Apply the Changes

Always validate your Nginx config for errors before reloading:

nginx -t

If the test passes, reload Nginx to make the changes live:

systemctl reload nginx

Bonus: Log IP Requests (Optional)

If you want to monitor who's making these IP-based requests before blocking (or just to confirm the block is working), add log directives to your default server block:

server {
    # ... existing default server config ...

    access_log /var/log/nginx/ip_access.log;
    error_log /var/log/nginx/ip_error.log;
}

This lets you review traffic patterns and ensure you're not blocking any legitimate requests (though you mentioned you don't have any in this case).


内容的提问来源于stack exchange,提问作者Turgs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:21:18