【问题标题】:Using google maps api behind firewall在防火墙后面使用谷歌地图 api
【发布时间】:2011-04-27 07:48:38
【问题描述】:

我有一个嵌入谷歌地图的应用程序。工作正常。一些用户位于防火墙后面,对世界其他地方的访问非常有限。

有人知道 google maps api 使用的 dns-names/ip-addresses 的有效列表吗?我可以在 firebug 的网络面板中看到它加载的 dns 名称。但是只使用它们感觉有点不安全。有没有这样的列表可以添加到防火墙白名单中?

..弗雷德里克

编辑

我与在谷歌地图团队工作的人交谈过。他说这是不可能的,因为 ip 地址发生了变化,因为地图服务在服务器的整个范围内被分割。

【问题讨论】:

    标签: google-maps firewall


    【解决方案1】:

    正如我在 Chrome 的控制台中看到的那样,谷歌地图目前正在使用 3 台服务器:

    • mt0.google.com (ew-in-f100.1e100.net)
    • mt1.google.com (ew-in-f102.1e100.net)
    • maps.gstatic.com (ew-in-f104.1e100.net)

    如您所见,它们都在1e100.net 域中。

    1e100等于1 googol;)

    【讨论】:

      【解决方案2】:

      这现在是可能的。主要信息来源在这里:https://developers.google.com/maps/documentation/business/articles/prelaunch_checklist#firewall

      配置防火墙以允许访问 Google Maps API 服务

      为什么重要: Maps API 服务使用多种域,其中一些不属于 *google.com 域。如果您位于限制性防火墙之后,请务必了解哪些 Maps API 服务使用哪些域。

      未能允许访问正确的域将导致 API 请求失败,这可能会破坏您的应用程序。有关 Maps API 使用的域的完整列表,请咨询我们的portal resource(需要登录):

      登录Google Enterprise Support Portal 支持门户仅适用于 Google Maps API for Work 用户。 导航到“资源”选项卡 选择名为"List of domains used by the Google Maps API Family." 的资源 您应该允许您的应用程序访问这些域。

      请注意,我们不建议按 IP 地址管理防火墙限制,因为与这些域关联的 IP 不是静态的。

      【讨论】:

        【解决方案3】:

        这是有关 Google Maps API 中使用的域的文章的内容。这篇文章可在 Google Cloud 支持门户中找到:

        本文档列出了加载地图组件时谷歌地图平台使用的所有域。提供此域列表是为了帮助您设置防火墙配置,以防您的 Internet 访问被每个域策略过滤。

        重要提示

        • 随着新功能的推出,此列表可能会发生变化,并且可能不是最新的,因为会注意到新的域。建议每 2 个月检查一次此页面。
        • 以下包含 google.com 的条目可以替换为 Google 地图推出的其他域:maps.google.co.uk、ditu.google.com、bendi.google.com、ditu.google.cn、bendi .google.cn、mapy.google.pl等
        • 从中国访问 API 的用户,除了 google.com 和 gstatic.com 之外,还会分别向 google.cn 和 gstatic.cn 下的域发送请求。

        基于 HTTP 的 JavaScript 地图 API(V2 和 V3)

        Maps Javascript API V3(和 V2)引导程序和服务(地理编码、行车路线、海拔、公里数)使用:

        • maps.google.com
        • maps.googleapis.com

        静态依赖:

        • maps.gstatic.com

        地图图块和交通图块:

        • maps.googleapis.com

        空中瓷砖:

        • khmdb0.google.com
        • khmdb0.googleapis.com
        • khmdb1.google.com
        • khmdb1.googleapis.com

        卫星图块:

        • khm.google.com
        • khm.googleapis.com
        • khm0.google.com
        • khm0.googleapis.com
        • khm1.google.com
        • khm1.googleapis.com
        • khms0.google.com
        • khms0.googleapis.com
        • khms1.google.com
        • khms1.googleapis.com

        街景图像:

        • geo0.ggpht.com
        • geo1.ggpht.com
        • geo2.ggpht.com
        • geo3.ggpht.com
        • lh3.ggpht.com
        • lh4.ggpht.com
        • lh5.ggpht.com
        • lh6.ggpht.com
        • cbk0.google.com
        • cbk0.googleapis.com
        • cbk1.google.com
        • cbk1.googleapis.com
        • cbk2.google.com
        • cbk2.googleapis.com
        • cbk3.google.com
        • cbk3.googleapis.com
        • lh3.googleusercontent.com
        • lh4.googleusercontent.com
        • lh5.googleusercontent.com
        • lh6.googleusercontent.com

        报告请求:

        • gg.google.com

        识别请求:

        • id.google.com

        基于 HTTPS 的 Javascript 地图 API(V2 和 V3)

        Maps Javascript API V3(和 V2)引导程序和服务(地理编码、行车路线、海拔、公里数)使用:

        • maps-api-ssl.google.com
        • maps.googleapis.com

        静态依赖:

        • maps-api-ssl.google.com
        • maps.gstatic.com

        地图图块和交通图块:

        • maps.googleapis.com

        空中瓷砖:

        • khmdb0.google.com
        • khmdb0.googleapis.com
        • khmdb1.google.com
        • khmdb1.googleapis.com

        卫星图块:

        • khm.google.com
        • khm.googleapis.com
        • khm0.google.com
        • khm0.googleapis.com
        • khm1.google.com
        • khm1.googleapis.com
        • khms0.google.com
        • khms0.googleapis.com
        • khms1.google.com
        • khms1.googleapis.com
        • khms2.google.com
        • khms2.googleapis.com
        • khms3.google.com
        • khms3.googleapis.com

        街景图像:

        • geo0.ggpht.com
        • geo1.ggpht.com
        • geo2.ggpht.com
        • geo3.ggpht.com
        • lh3.ggpht.com
        • lh4.ggpht.com
        • lh5.ggpht.com
        • lh6.ggpht.com
        • cbks0.google.com
        • cbks0.googleapis.com
        • cbks1.google.com
        • cbks1.googleapis.com
        • cbks2.google.com
        • cbks2.googleapis.com
        • cbks3.google.com
        • cbks3.googleapis.com
        • lh3.googleusercontent.com
        • lh4.googleusercontent.com
        • lh5.googleusercontent.com
        • lh6.googleusercontent.com

        报告请求:

        • gg.google.com

        不发送识别请求。

        其他域

        您可能还会看到 javascript v3 API 访问以下域:

        • googleapis.l.google.com
        • clients.l.google.com
        • maps.l.google.com
        • mt.l.google.com
        • khm.l.google.com
        • csi.gstatic.com

        地图 API 网络服务

        Geocoding API V3(和 V2)、Directions API、Elevation API、Distance Matrix API 和 Static Maps API V2(和 V1)使用:

        通过 HTTP:

        • maps.google.com(旧版)
        • maps.googleapis.com(推荐)

        通过 HTTPS:

        • maps-api-ssl.google.com(旧版)
        • maps.googleapis.com(推荐)

        地图 Android SDK

        Maps Android SDK 通过 HTTPS 使用这些域:

        • clients4.google.com
        • www.google.com
        • csi.gstatic.com

        【讨论】:

        • 能否提供原链接?
        • 此信息仅供使用 Google 地图高级计划的用户使用,邮箱为google.secure.force.com
        • 谢谢。我没有高级计划,所以我没有找到这个。您是否有任何信息,如果是“正常计划”,域规则是什么?我找不到任何相关信息。
        猜你喜欢
        • 2021-05-05
        • 2017-11-02
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        相关资源
        最近更新 更多