通过IP访问WSL中Apache报403 Forbidden,主机名访问正常求助
Hey Frank, let's break down why you're hitting that 403 error when accessing your Apache server via IPv4 (192.168.1.10) but not via the hostname mmtserver. That IPv6 ping response is a useful clue, but let's cover all bases step by step:
1. Check for Virtual Host Configuration Mismatch
It’s likely your Apache setup has a dedicated virtual host tuned for mmtserver, while requests to the raw IPv4 are falling back to the default virtual host (which might have stricter access rules).
- Navigate to your sites-available directory to inspect config files:
cd /etc/apache2/sites-available/ - Look for a config file referencing
mmtserver(e.g.,mmtserver.conf). Open it and check the<VirtualHost>directive—if it’s set to<VirtualHost mmtserver:80>instead of<VirtualHost *:80>, only hostname-based requests will match this config. - For the default config (usually
000-default.conf), verify its<Directory>block explicitly allows access to your web root (like/var/www/html).
2. Fix Apache 2.4 Access Control Syntax
Apache 2.4 uses a modern access control system, and mixing old syntax (from 2.2 and earlier) can cause silent failures that lead to 403s—even if you think you’ve allowed all traffic.
- Replace any legacy
Order allow,deny/Allow from allrules with the 2.4-compliant syntax in your directory blocks:<Directory /var/www/html> Options Indexes FollowSymLinks AllowOverride None # Use this instead of the old Order/Allow rules Require all granted </Directory> - If you need to keep using the old syntax for compatibility, ensure the
mod_access_compatmodule is enabled:sudo a2enmod access_compat sudo systemctl restart apache2
3. Fix WSL File Permission Quirks
WSL can have odd permission issues that block Apache from reading your web files, even if your config says access is allowed.
- Set the correct owner and permissions for your web root:
This ensures the Apache runtime user (sudo chown -R www-data:www-data /var/www/html sudo chmod -R 755 /var/www/htmlwww-data) has read/execute access to directories and read access to files.
4. Verify Apache’s IPv4/IPv6 Listening Settings
Your ping to mmtserver returning an IPv6 address means the hostname resolves to IPv6 first—so Apache might handle IPv6 requests correctly but fail on IPv4.
- Open
/etc/apache2/ports.confand confirm it listens on both protocols:Listen 0.0.0.0:80 Listen [::]:80 - Restart Apache to apply changes:
sudo systemctl restart apache2
5. Use Apache Error Logs to Pinpoint the Exact Issue
This is the most critical step—logs will tell you exactly why the 403 is happening, no guessing required.
- Tail the error log in real-time while testing the IPv4 access:
sudo tail -f /var/log/apache2/error.log - From
192.168.1.107, try accessinghttp://192.168.1.10again. Look for key error lines:client denied by server configuration: Your access control rules are blocking the requestpermission denied: Apache can’t read the file/directory due to filesystem permissions
Start with checking the error logs first—it’ll narrow down the problem faster than anything else. Let me know what the logs say if you’re still stuck!
内容的提问来源于stack exchange,提问作者Frank

