Require IP but disallow if x-forwarded-for

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












I'm trying to write a rule for a location within httpd config.



Apache ver.2.4



Currently I have this configured:



<Location /location>
Require ip 192.168.0.0/255.255.0.0
</Location>


Which allows it from anywhere within the local subnet.



But as these request come from the local loadbalancer-proxy it will still allow it.



How to write this to deny anything which has a remote IP or it was x-forwaded-for ?



Something like:



<Location /location>
Require ip 192.168.0.0/255.255.0.0
Require not remote ip *
</Location>


or



<Location /location>
Order Deny,Allow
Allow from All
SetEnvIf X-Forwarded-For "*" DenyAccess
Deny from env=DenyAccess
</Location>


Thanks!







share|improve this question
























    up vote
    0
    down vote

    favorite












    I'm trying to write a rule for a location within httpd config.



    Apache ver.2.4



    Currently I have this configured:



    <Location /location>
    Require ip 192.168.0.0/255.255.0.0
    </Location>


    Which allows it from anywhere within the local subnet.



    But as these request come from the local loadbalancer-proxy it will still allow it.



    How to write this to deny anything which has a remote IP or it was x-forwaded-for ?



    Something like:



    <Location /location>
    Require ip 192.168.0.0/255.255.0.0
    Require not remote ip *
    </Location>


    or



    <Location /location>
    Order Deny,Allow
    Allow from All
    SetEnvIf X-Forwarded-For "*" DenyAccess
    Deny from env=DenyAccess
    </Location>


    Thanks!







    share|improve this question






















      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      I'm trying to write a rule for a location within httpd config.



      Apache ver.2.4



      Currently I have this configured:



      <Location /location>
      Require ip 192.168.0.0/255.255.0.0
      </Location>


      Which allows it from anywhere within the local subnet.



      But as these request come from the local loadbalancer-proxy it will still allow it.



      How to write this to deny anything which has a remote IP or it was x-forwaded-for ?



      Something like:



      <Location /location>
      Require ip 192.168.0.0/255.255.0.0
      Require not remote ip *
      </Location>


      or



      <Location /location>
      Order Deny,Allow
      Allow from All
      SetEnvIf X-Forwarded-For "*" DenyAccess
      Deny from env=DenyAccess
      </Location>


      Thanks!







      share|improve this question












      I'm trying to write a rule for a location within httpd config.



      Apache ver.2.4



      Currently I have this configured:



      <Location /location>
      Require ip 192.168.0.0/255.255.0.0
      </Location>


      Which allows it from anywhere within the local subnet.



      But as these request come from the local loadbalancer-proxy it will still allow it.



      How to write this to deny anything which has a remote IP or it was x-forwaded-for ?



      Something like:



      <Location /location>
      Require ip 192.168.0.0/255.255.0.0
      Require not remote ip *
      </Location>


      or



      <Location /location>
      Order Deny,Allow
      Allow from All
      SetEnvIf X-Forwarded-For "*" DenyAccess
      Deny from env=DenyAccess
      </Location>


      Thanks!









      share|improve this question











      share|improve this question




      share|improve this question










      asked Dec 14 '17 at 14:25









      DaWe4444

      639




      639

























          active

          oldest

          votes











          Your Answer







          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "106"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: false,
          noModals: false,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );








           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f410881%2frequire-ip-but-disallow-if-x-forwarded-for%23new-answer', 'question_page');

          );

          Post as a guest



































          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes










           

          draft saved


          draft discarded


























           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f410881%2frequire-ip-but-disallow-if-x-forwarded-for%23new-answer', 'question_page');

          );

          Post as a guest













































































          Popular posts from this blog

          How to check contact read email or not when send email to Individual?

          Bahrain

          Postfix configuration issue with fips on centos 7; mailgun relay