博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
使用nginx代理后以及配置https后,如何获取真实的ip地址
阅读量:5044 次
发布时间:2019-06-12

本文共 4313 字,大约阅读时间需要 14 分钟。

使用nginx代理后以及配置https后,如何获取真实的ip地址

Date:2018-8-27 14:15:51

使用nginx, apache等反向代理后,如果想获取请求的真实ip,要在nginx中配置,把当前请求的ip等信息携带去请求应用服务。

1.配置nginx的https servler

  • nginx.conf配置
server {        listen       80;        server_name  edudemo.XXX.com;        # 如果配置了下面的rewrite,下面的location就没用了,会直接转发到下面的https去请求        rewrite ^(.*)$ https://$host$1 permanent;        location / {            proxy_pass   https://edudemo.XXX.com;            proxy_set_header Host $host;            proxy_set_header X-real-ip $remote_addr;            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;        }}server {    listen 443;    server_name edudemo.XXX.com;    ssl on;    root html;    index index.html index.htm;    ssl_certificate   cert/214421564860931.pem;    ssl_certificate_key  cert/214421564860931.key;    ssl_session_timeout 5m;    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;    ssl_prefer_server_ciphers on;    location / {        proxy_pass   http://127.0.0.1:8083;        # 获取请求的host        proxy_set_header Host $host;        # 获取请求的ip地址        proxy_set_header X-real-ip $remote_addr;        # 获取请求的多级ip地址,当请求经过多个反向代理时,会获取多个ip,英文逗号隔开        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;    }}

2.代码中获取真实的ip地址

/**     * 获取请求主机IP地址,如果通过代理进来,则透过防火墙获取真实IP地址;     *      * @param request     * @return     * @throws IOException     */    public final static String getIpAddress(HttpServletRequest request) throws IOException {        // 获取nginx代理前的ip地址        String ip = request.getHeader("X-real-ip");        if (logger.isInfoEnabled()) {            logger.info("getIpAddress(X-real-ip) - X-real-ip - String ip=" + ip);        }        // 获取所有代理记录的ip地址        String refererIps = request.getHeader("x-forwarded-for");        String[] split = refererIps.trim().split(",");        if (split != null && split.length >= 2) {            // 获取请求最开始的ip            ip = split[0];            logger.info("getIpAddress(x-forwarded-for) - x-forwarded-for - String ip=" + refererIps);        }        if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {            if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {                ip = request.getHeader("Proxy-Client-IP");                if (logger.isInfoEnabled()) {                    logger.info("getIpAddress(HttpServletRequest) - Proxy-Client-IP - String ip=" + ip);                }            }            if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {                ip = request.getHeader("WL-Proxy-Client-IP");                if (logger.isInfoEnabled()) {                    logger.info("getIpAddress(HttpServletRequest) - WL-Proxy-Client-IP - String ip=" + ip);                }            }            if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {                ip = request.getHeader("HTTP_CLIENT_IP");                if (logger.isInfoEnabled()) {                    logger.info("getIpAddress(HttpServletRequest) - HTTP_CLIENT_IP - String ip=" + ip);                }            }            if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {                ip = request.getHeader("HTTP_X_FORWARDED_FOR");                if (logger.isInfoEnabled()) {                    logger.info("getIpAddress(HttpServletRequest) - HTTP_X_FORWARDED_FOR - String ip=" + ip);                }            }            if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {                ip = request.getRemoteAddr();                if (logger.isInfoEnabled()) {                    logger.info("getIpAddress(HttpServletRequest) - getRemoteAddr - String ip=" + ip);                }            }        } else if (ip.length() > 15) {            String[] ips = ip.split(",");            for (int index = 0; index < ips.length; index++) {                String strIp = (String) ips[index];                if (!("unknown".equalsIgnoreCase(strIp))) {                    ip = strIp;                    break;                }            }        }        logger.info("final request ip : {}", ip);        return ip;    }

获取到真实的ip后就可以去对用户进行限制了,ip访问次数限制,ip黑名单过滤。。。

参考:https://www.cnblogs.com/zhanghaoh/p/5293158.html

转载于:https://www.cnblogs.com/chaos-x/p/9541952.html

你可能感兴趣的文章
内部类
查看>>
树链剖分入门
查看>>
图解算法时间复杂度
查看>>
UI_搭建MVC
查看>>
一个样例看清楚JQuery子元素选择器children()和find()的差别
查看>>
代码实现导航栏分割线
查看>>
Windows Phone开发(7):当好总舵主 转:http://blog.csdn.net/tcjiaan/article/details/7281421...
查看>>
VS 2010打开设计器出现错误
查看>>
SQLServer 镜像功能完全实现
查看>>
Vue-详解设置路由导航的两种方法
查看>>
一个mysql主从复制的配置案例
查看>>
大数据学习系列(8)-- WordCount+Block+Split+Shuffle+Map+Reduce技术详解
查看>>
dvwa网络渗透测试环境的搭建
查看>>
Win8 安装VS2012 和 Sql Server失败问题
查看>>
过点(2,4)作一直线在第一象限与两轴围成三角形,问三角形面积的最小值?...
查看>>
java aes CBC的填充方式发现
查看>>
使用ionic cordova build android --release --prod命令打包报有如下错误及解决方法
查看>>
BZOJ 2338 HNOI2011 数矩形 计算几何
查看>>
关于页面<!DOCTYPE>声明
查看>>
【AS3代码】播放FLV视频流的三步骤!
查看>>