IIS7 URL Rewrite实现从默认网站子路径访问路由器Web管理界面
Complete IIS URL Rewrite/ARR Setup for Accessing Home Router Admin via Main Site
Alright, let's get this sorted out— I’ve set up exactly this reverse proxy setup for my home router using IIS URL Rewrite and ARR, so I know exactly what works and where people usually trip up. Here’s a step-by-step working configuration:
Prerequisites First
- Make sure your IIS server has both URL Rewrite and Application Request Routing (ARR) modules installed (ARR is critical— don’t skip this; it’s what makes the reverse proxy work beyond basic redirects).
- Your router’s admin interface has a fixed internal IP (e.g.,
192.168.1.1) and you know its port (default is usually 80, sometimes 8080). - Your main site (
http://example.com) is already running properly in IIS.
Step 1: Enable ARR Proxy on Your IIS Server
- Open IIS Manager, select the server-level node (not your individual site).
- Find the Application Request Routing Cache feature in the middle pane.
- On the right-hand "Actions" bar, click Server Proxy Settings.
- Check the box for Enable proxy, then click Apply at the top right. This tells IIS it can forward requests to other servers (your router, in this case).
Step 2: Configure URL Rewrite Rules on Your Main Site
Head to your example.com site in IIS, open the URL Rewrite module:
2.1 Create the Inbound Rewrite Rule (Map /router1/* to Router’s IP)
- Click Add Rule(s) > Select Reverse Proxy (this is easier than building rules from scratch, as it auto-sets up basic ARR integration).
- In the popup, enter your router’s internal address (e.g.,
192.168.1.1:80) and check Enable SSL offloading (harmless even if your router uses plain HTTP). Click OK. - Now edit the auto-generated inbound rule:
- Go to the Pattern section, change the regex to
^router1/(.*)(this captures everything after/router1/to pass to the router). - In the Action section, set the Rewrite URL to
http://192.168.1.1/{R:1}(replace with your router’s IP/port). Check Append query string and Stop processing of subsequent rules. - Click Apply.
- Go to the Pattern section, change the regex to
2.2 Fix the Outbound Rewrite Rule (Replace Router’s Internal URLs in Responses)
The router’s admin page will include links pointing to its internal IP (like http://192.168.1.1/index.cgi), which will break when accessed from your main site. We need to rewrite these in the response:
- Find the auto-generated outbound rule (named something like "ReverseProxyOutboundRule1") and edit it.
- In the Match section:
- Set Matching scope to
Server. - Set Pattern to
http://192.168.1.1(/.*)?(this catches any reference to the router’s IP).
- Set Matching scope to
- In the Action section:
- Set Value to
http://example.com/router1{R:1}(replaces the internal IP with your main site’s/router1path). - Check Apply rewrite to: Response headers and Response body to make sure all links, images, and styles get updated.
- Set Value to
- Click Apply.
Step 3: Router-Side Adjustments (If Needed)
Some routers have security settings that block reverse-proxied requests:
- Look for an option like HTTP Referer Check or Host Header Validation in your router’s admin panel and disable it (this prevents the router from rejecting requests coming from your IIS server).
- If your router redirects all requests back to its internal IP (e.g., a 302 redirect), the outbound rule we set up should catch and rewrite the
Locationheader automatically— but if not, add a dedicated outbound rule forLocationheaders using the same pattern/replacement as above.
Step 4: Test It Out
- Visit
http://example.com/router1/index.cgi— you should see your router’s login page. - Click any link in the router’s interface (e.g., "Wireless Settings")— the URL should stay as
http://example.com/router1/[some-path].cgiinstead of jumping to the internal IP. - If styles/images are broken, double-check that the outbound rule is applied to the response body (sometimes routers use absolute paths for static assets that need rewriting).
Common Pitfalls to Avoid
- Forgetting to enable ARR Proxy: This is the #1 reason reverse proxy setups fail in IIS— you can have perfect rewrite rules, but ARR needs to be enabled to forward the request.
- Incorrect regex patterns: Make sure your inbound rule’s pattern captures the full path after
/router1/using(.*)and passes it with{R:1}. - Router security blocks: If you get a 403 or blank page, check your router’s security settings to allow requests from your IIS server’s internal IP.
内容的提问来源于stack exchange,提问作者BarryP
相关产品推荐
相关产品推荐

