如何过滤请求让Apache处理而非Tomcat?Tomcat闲置自动关机配置咨询
Hey there! Let’s break down how to solve your two key problems, plus make that idle auto-shutdown work smoothly for your Debian 4.9.88 setup with Tomcat 8.5.29 and Apache.
Since your only app lives at http://hostname/source/, we need to set up Apache so it only forwards /source/ requests to Tomcat—all other traffic gets handled directly by Apache (or blocked). Here’s how:
First, make sure Apache has the necessary proxy modules enabled. Run these commands:
a2enmod proxy proxy_http systemctl restart apache2
Next, edit your Apache virtual host config (usually at /etc/apache2/sites-available/000-default.conf or your custom site file) and add these rules:
<VirtualHost *:80> ServerName hostname # Forward only /source/ requests to Tomcat (adjust Tomcat port if needed) ProxyPass /source/ http://localhost:8080/source/ ProxyPassReverse /source/ http://localhost:8080/source/ # Block all other requests (or serve a custom forbidden page) <Location "/"> Order deny,allow Deny from all # Uncomment below to use a custom page instead of 403 # ErrorDocument 403 /custom-forbidden.html </Location> </VirtualHost>
Save the config, restart Apache again, and now only traffic to /source/ will hit Tomcat—everything else stays with Apache.
Those annoying scans (like GET /, POST /GponForm/diag_Form?images/, and GET /jmx-conso...) can be stopped with Apache’s mod_rewrite—it’s simple and effective.
First, enable the rewrite module:
a2enmod rewrite systemctl restart apache2
Add these rules to your virtual host config or a .htaccess file in your Apache root:
RewriteEngine On # Block root (GET /) requests RewriteRule ^/$ - [R=403,L] # Block requests targeting GponForm paths RewriteRule ^/GponForm/ - [R=403,L] # Block jmx-console and similar admin scan paths RewriteRule ^/jmx-conso - [R=403,L] # Add more rules for common scan targets if needed RewriteRule ^/(admin|manager|console|test) - [R=403,L]
For extra toughness, replace R=403 with R=444—this tells Apache to close the connection immediately instead of sending a 403 response, which is harder on scanners.
If you want even more protection, install mod_evasive to block brute-force attacks:
apt-get install libapache2-mod-evasive
You can tweak its config (usually at /etc/apache2/mods-available/evasive.conf) to limit request rates from single IPs.
You already have a script monitoring Tomcat’s last access time—now that we’ve filtered requests to only /source/ hitting Tomcat, you can refine the script to focus solely on those valid app requests.
Here’s a quick tweak idea:
- Point your script to Tomcat’s access log (typically
/var/log/tomcat8/localhost_access_log.*.txt) - Filter for lines containing
/source/to get the last valid app access time - If the time since that last access exceeds your threshold (e.g., 1 hour), run
shutdown -h now
Then set up a cron job to run the script every 10 minutes (adjust frequency as needed):
crontab -e # Add this line (replace with your script path) */10 * * * * /home/your-user/scripts/idle-shutdown-check.sh
That’s it—your server will now shut down automatically when it’s been idle for your set period, without false triggers from malicious scans.
内容的提问来源于stack exchange,提问作者Brian Utterback

