【问题标题】:IP restriction not working when following documentation of Windows Azure遵循 Windows Azure 文档时 IP 限制不起作用
【发布时间】:2013-02-21 10:43:28
【问题描述】:

我想尝试限制对基于 IP 的“云服务”的 webrole 的访问。 this article 中有一个很好的文档,但是当我遵循它时,我在部署它时遇到错误。

我得到的错误是:
Recycling (Role has encountered an error and has stopped. Application startup task failed with exit code 1

这是错误的部分

%windir%\system32\inetsrv\AppCmd.exe unlock config -section:system.webServer/security/ipSecurity

所以我认为命令是错误的,我在 Windows 2012 操作系统上运行 Webrole。

当只添加 web.config 部分时,没有任何变化,它不起作用

<system.webServer>
    <security>
        <!—Unlisted IP addresses are denied access–>
        <ipSecurity allowUnlisted=”false”>
        <!—The following IP addresses are granted access–>
            <add allowed=”true” ipAddress=”192.168.100.1” subnetMask=”255.255.0.0″ />
           <add allowed=”true” ipAddress=”192.168.100.2″ subnetMask=”255.255.0.0″ />
        </ipSecurity>
    </security>
</system.webServer>

有没有这方面的经验,谁能帮帮我?

【问题讨论】:

    标签: azure azure-web-roles ip-restrictions


    【解决方案1】:

    如果您通过 RDP 登录到任何正在运行的 Windows azure 云服务实例并以提升的权限启动命令行,您可以在启动脚本中使用这些命令之前对其进行测试。这样您可能会收到正确的错误消息。

    我在我的一个 Azure 实例上尝试过,我注意到:

    %windir%\system32\inetsrv\AppCmd.exe unlock config - section:system.webServer/security/ipSecurity
    

    从不退出,但

    %windir%\system32\inetsrv\AppCmd.exe unlock config /section:system.webServer/security/ipSecurity
    

    成功了。

    【讨论】:

    • 尼科,感谢您的回复。你用命令纠正它。但是还有更多的东西可以让这个工作。您还必须在 IIS 中安装功能 IP 地址和域限制。然后您可以根据我的问题中发布的Microsoft文档设置限制。
    • 使用启动命令在 IIS 中安装功能 IP 地址和域限制 >>> PowerShell Install-WindowsFeature -Name Web-IP-Security
    猜你喜欢
    • 1970-01-01
    • 2011-10-30
    • 2011-02-10
    • 1970-01-01
    • 2013-12-14
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多