如何阻止使用服务器IP而非域名访问Nginx站点的请求?
Got it, let's tackle this problem head-on. Blocking requests that use your server's IP address instead of your domain is a smart move to cut down on suspicious traffic and reduce your attack surface. Here are the most reliable methods to implement this:
1. Use a Default Server Block to Reject IP Requests
Nginx routes requests to the first matching server block, or a designated "default" one if no domain match is found. We can create a dedicated default block to immediately drop any IP-based requests.
Add this configuration to your Nginx setup (either in /etc/nginx/nginx.conf or a separate file in /etc/nginx/conf.d/):
server { listen 80 default_server; listen [::]:80 default_server; listen 443 ssl default_server; listen [::]:443 ssl default_server; # For SSL, use a self-signed cert if you don't have a domain-specific one here ssl_certificate /path/to/self-signed.crt; ssl_certificate_key /path/to/self-signed.key; server_name _; # Catches any server name (including raw IPs) # Return 444: Nginx-specific code that closes the connection without a response return 444; # Alternatively, send a 403 Forbidden if you want to explicitly deny access: # return 403; }
return 444is ideal because it gives attackers no feedback about your server, making probing harder.- To generate a self-signed SSL cert, run this command:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /path/to/self-signed.key -out /path/to/self-signed.crt
2. Enforce Host Header Matching in Your Main Server Blocks
If you want to double down and ensure only requests with your valid domain in the Host header get through, add this check inside your existing domain-specific server blocks:
server { listen 80; listen [::]:80; listen 443 ssl; listen [::]:443 ssl; server_name yourdomain.com www.yourdomain.com; # Block any request where the Host header doesn't match your domain if ($host !~* ^(yourdomain.com|www.yourdomain.com)$) { return 444; } # Rest of your server configuration (root, index, location blocks, etc.) root /var/www/yourdomain; index index.html; }
This catches any sneaky requests that might use your IP but spoof a non-matching Host header.
3. Test and Apply the Changes
Always validate your Nginx config for errors before reloading:
nginx -t
If the test passes, reload Nginx to make the changes live:
systemctl reload nginx
Bonus: Log IP Requests (Optional)
If you want to monitor who's making these IP-based requests before blocking (or just to confirm the block is working), add log directives to your default server block:
server { # ... existing default server config ... access_log /var/log/nginx/ip_access.log; error_log /var/log/nginx/ip_error.log; }
This lets you review traffic patterns and ensure you're not blocking any legitimate requests (though you mentioned you don't have any in this case).
内容的提问来源于stack exchange,提问作者Turgs

