IIS 10中HTTP转HTTPS重写规则失效,访问HTTP返回空响应
Let’s work through this step by step—your rewrite rules are close, but there are a few key things to check that might be causing the ERR_EMPTY_RESPONSE error when accessing HTTP.
First, Fix the Rule Syntax Mismatch
Looking at your first rule, you set patternSyntax="Wildcard" but used a regex-style pattern (^OFF$) for the {HTTPS} condition. Wildcard mode doesn’t recognize regex anchors like ^ and $—it treats them as literal characters. That means your condition will never match, but the empty response suggests there’s more going on than just a rule syntax issue. Let’s fix the rule first, then check critical site settings.
Corrected Rule Options:
Option 1 (Regex Mode, Recommended):
Switch patternSyntax to ECMAScript (IIS’s default regex mode) so your ^OFF$ pattern works as intended:
<rule name="Redirect to HTTPS" enabled="true" patternSyntax="ECMAScript" stopProcessing="true"> <match url="(.*)" /> <conditions logicalGrouping="MatchAll"> <add input="{HTTPS}" pattern="^OFF$" /> </conditions> <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" /> </rule>
Option 2 (Wildcard Mode):
If you prefer Wildcard syntax, remove the regex anchors and use a simple wildcard match for the URL:
<rule name="Redirect to HTTPS" enabled="true" patternSyntax="Wildcard" stopProcessing="true"> <match url="*" /> <conditions logicalGrouping="MatchAll"> <add input="{HTTPS}" pattern="OFF" /> </conditions> <action type="Redirect" url="https://{HTTP_HOST}/{R:0}" redirectType="Permanent" /> </rule>
Check if IIS is Blocking HTTP Traffic Outright
The most common cause of ERR_EMPTY_RESPONSE for HTTP requests is that IIS rejects HTTP before the rewrite rule can run:
- SSL Settings Check: Go to your site’s
SSL Settingsin IIS Manager. If Require SSL is checked, IIS will immediately drop any HTTP request (no redirect, just an empty response). Uncheck this box—your rewrite rule will handle redirecting to HTTPS instead. - 80 Port Binding Validation: You mentioned binding port 80 without a hostname. Double-check:
- Is the binding set to
All UnassignedIP address? If you bound it to a specific IP that’s not accessible externally, requests will fail. - Are other sites using port 80? IIS allows only one site per IP:port combination. Use
netstat -anoin Command Prompt to check if port 80 is occupied by another process or site.
- Is the binding set to
Verify Firewall/Security Group Allows Port 80
If your server is behind a firewall (Windows Firewall or cloud provider security group), ensure port 80 is open for inbound HTTP traffic:
- Windows Firewall: Go to
Windows Defender Firewall > Advanced Settings > Inbound Rulesand confirm there’s an enabled rule allowingHTTP (80)traffic. - Cloud Security Group: If using Azure/AWS/GCP, check that your instance’s security group has an inbound rule allowing port 80 from your client IP (or all IPs for public-facing sites).
Enable Rewrite Logs for Debugging
To confirm if your rule is even being evaluated, enable rewrite logs:
- In IIS Manager, select your site.
- Open
URL Rewrite> ClickView Server Variablesin the right pane. - Check
Log Rewrite Activityand set the log path (default is%SystemDrive%\inetpub\logs\LogFiles\W3SVC<SiteID>). - Reproduce the HTTP request, then check the logs. No entries mean the request isn’t reaching the rule (likely due to SSL settings or port blocking).
内容的提问来源于stack exchange,提问作者Bob Tway

