如何在IIS8.5上自定义HTTP转HTTPS重定向:外网强制HTTPS,内网保留HTTP
Solution to Redirect HTTP to HTTPS Only for External Visitors (Keep HTTP for Internal)
Got it, let's tweak your existing IIS rewrite rule to handle both external and internal access scenarios exactly as you need: forcing HTTP to HTTPS for internet visitors, while leaving HTTP available for internal users (like those connecting from 192.168.1.100). Here's the modified configuration:
<system.webServer> <rewrite> <rules> <rule name="HTTPS force for external only" enabled="true" stopProcessing="true"> <match url="(.*)" /> <conditions logicalGrouping="MatchAll"> <!-- Trigger only when HTTPS is not enabled --> <add input="{HTTPS}" pattern="^OFF$" /> <!-- Exclude internal IP addresses (adjust the pattern to match your internal subnet) --> <add input="{REMOTE_ADDR}" pattern="^192\.168\.1\.\d+$" negate="true" /> </conditions> <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" /> </rule> </rules> </rewrite> </system.webServer>
Key Details Breakdown:
logicalGrouping="MatchAll": Makes sure both conditions have to be true for the rule to run—so HTTPS is off and the visitor isn't coming from your internal 192.168.1.x subnet.negate="true"on the REMOTE_ADDR condition: This tells IIS to skip the redirect rule if the visitor's IP matches the internal subnet pattern. That means internal users on HTTP won't be sent to HTTPS.- Adjust the IP pattern for your network: If your internal setup uses a different subnet (like 10.0.0.x or 172.16.x.x), update the regex:
- For 10.0.0.0/8:
^10\.\d+\.\d+\.\d+$ - For a single specific IP (192.168.1.100):
^192\.168\.1\.100$
- For 10.0.0.0/8:
- Handling multiple internal subnets: If you need to exclude multiple ranges, just add more
<add>lines for each subnet. For example:<conditions logicalGrouping="MatchAll"> <add input="{HTTPS}" pattern="^OFF$" /> <add input="{REMOTE_ADDR}" pattern="^192\.168\.1\.\d+$" negate="true" /> <add input="{REMOTE_ADDR}" pattern="^10\.0\.0\.\d+$" negate="true" /> </conditions>
This setup ensures external users get automatically redirected to the secure HTTPS version, while your internal team can keep using HTTP without interruptions.
内容的提问来源于stack exchange,提问作者Amir Hussein Khaniki
相关产品推荐
相关产品推荐

