<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Centos on Youqing Han - DevOps Engineer</title>
    <link>https://hanyouqing.com/tags/centos/</link>
    <description>Recent content in Centos on Youqing Han - DevOps Engineer</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <managingEditor>ihanyouqing#gmail.com (#->@) (Youqing Han)</managingEditor>
    <webMaster>ihanyouqing#gmail.com (#->@) (Youqing Han)</webMaster>
    <lastBuildDate>Mon, 01 Sep 2025 10:00:00 +0800</lastBuildDate>
    <atom:link href="https://hanyouqing.com/tags/centos/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CentOS下Nginx配置地理访问控制：限制仅允许特定地区/国家访问</title>
      <link>https://hanyouqing.com/blog/2025/09/nginx-geo-access-control-centos/</link>
      <pubDate>Mon, 01 Sep 2025 10:00:00 +0800</pubDate><author>ihanyouqing#gmail.com (#->@) (Youqing Han)</author>
      <guid>https://hanyouqing.com/blog/2025/09/nginx-geo-access-control-centos/</guid>
      <description>&lt;h2 id=&#34;概述&#34;&gt;概述&lt;/h2&gt;&#xA;&lt;p&gt;需求来自某好友某生产环境，有古老的应用运行于远古的操作系统之上，年久失修，无人维护。某日，或老板/或领导/或客户，心血来潮提出一些需求，比如根据访问者的地理位置来限制对网站或API的访问。以应对以下场景：&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;合规性要求（如GDPR、数据本地化）&lt;/li&gt;&#xA;&lt;li&gt;许可证限制（某些服务仅在特定国家可用）&lt;/li&gt;&#xA;&lt;li&gt;安全防护（阻止来自特定地区的恶意流量）&lt;/li&gt;&#xA;&lt;li&gt;业务需求（仅服务特定市场）&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;本文将详细介绍在CentOS系统上配置Nginx实现地理访问控制的多种方法。&lt;/p&gt;&#xA;&lt;h2 id=&#34;方法一使用nginx-geoip模块推荐&#34;&gt;方法一：使用Nginx GeoIP模块（推荐）&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;注意：CentOS 7兼容性&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;在CentOS 7上，默认的Nginx包可能不包含GeoIP模块。如果遇到模块缺失问题，请参考以下解决方案：&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;检查现有Nginx是否支持GeoIP&lt;/strong&gt;：&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;nginx -V 2&amp;gt;&lt;span class=&#34;p&#34;&gt;&amp;amp;&lt;/span&gt;&lt;span class=&#34;m&#34;&gt;1&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;|&lt;/span&gt; grep -o with-http_geoip_module&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;如果支持，直接使用；如果不支持，选择以下方案之一&lt;/strong&gt;：&#xA;&lt;ul&gt;&#xA;&lt;li&gt;使用防火墙规则（方法二）&lt;/li&gt;&#xA;&lt;li&gt;使用第三方服务（方法三）&lt;/li&gt;&#xA;&lt;li&gt;重新编译Nginx（见下方安装步骤）&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h3 id=&#34;1-安装geoip模块&#34;&gt;1. 安装GeoIP模块&lt;/h3&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 安装EPEL仓库&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo yum install -y epel-release&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 安装GeoIP工具和数据库&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;yum -y install GeoIP GeoIP-devel GeoIP-data.noarch GeoIP geoipupdate geoipupdate-cron&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 检查Nginx是否已安装GeoIP模块&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;nginx -V 2&amp;gt;&lt;span class=&#34;p&#34;&gt;&amp;amp;&lt;/span&gt;&lt;span class=&#34;m&#34;&gt;1&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;|&lt;/span&gt; grep -o with-http_geoip_module&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 如果没有GeoIP模块，需要重新编译Nginx&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 安装编译依赖&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo yum groupinstall -y &lt;span class=&#34;s2&#34;&gt;&amp;#34;Development Tools&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo yum install -y pcre-devel zlib-devel openssl-devel libxml2-devel libxslt-devel gd-devel perl-devel perl-ExtUtils-Embed&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 安装Google perftools（如果启用该模块）&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo yum install -y gperftools gperftools-devel&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 下载Nginx源码并编译（如果需要）&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;wget http://nginx.org/download/nginx-1.28.0.tar.gz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;tar -xvf nginx-1.28.0.tar.gz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;cd&lt;/span&gt; nginx-1.28.0&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 参数从原 nginx -V 中获取，追加 --with-http_geoip_module &lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;./configure --prefix&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/usr/share/nginx --sbin-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/usr/sbin/nginx --modules-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/usr/lib64/nginx/modules --conf-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/etc/nginx/nginx.conf --error-log-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/log/nginx/error.log --http-log-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/log/nginx/access.log --http-client-body-temp-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/lib/nginx/tmp/client_body --http-proxy-temp-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/lib/nginx/tmp/proxy --http-fastcgi-temp-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/lib/nginx/tmp/fastcgi --http-uwsgi-temp-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/lib/nginx/tmp/uwsgi --http-scgi-temp-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/var/lib/nginx/tmp/scgi --pid-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/run/nginx.pid --lock-path&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;/run/lock/subsys/nginx --user&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;nginx --group&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;nginx --with-compat --with-debug --with-file-aio --with-google_perftools_module --with-http_addition_module --with-http_auth_request_module --with-http_dav_module --with-http_degradation_module --with-http_flv_module --with-http_gunzip_module --with-http_gzip_static_module --with-http_image_filter_module&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;dynamic --with-http_mp4_module --with-http_perl_module&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;dynamic --with-http_random_index_module --with-http_realip_module --with-http_secure_link_module --with-http_slice_module --with-http_ssl_module --with-http_stub_status_module --with-http_sub_module --with-http_v2_module --with-http_xslt_module&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;dynamic --with-mail&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;dynamic --with-mail_ssl_module --with-pcre --with-pcre-jit --with-stream&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;dynamic --with-stream_ssl_module --with-stream_ssl_preread_module --with-threads --with-cc-opt&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=generic&amp;#39;&lt;/span&gt; --with-ld-opt&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;-Wl,-z,relro -specs=/usr/lib/rpm/redhat/redhat-hardened-ld -Wl,-E&amp;#39;&lt;/span&gt; --with-http_geoip_module &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make &lt;span class=&#34;o&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo make install&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 检查Nginx是否支持GeoIP模块&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;/usr/sbin/nginx -V 2&amp;gt;&lt;span class=&#34;p&#34;&gt;&amp;amp;&lt;/span&gt;&lt;span class=&#34;m&#34;&gt;1&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;|&lt;/span&gt; grep -o with-http_geoip_module&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id=&#34;2-下载maxmind-geoip数据库&#34;&gt;2. 下载MaxMind GeoIP数据库&lt;/h3&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# # 创建目录&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# sudo mkdir -pv /usr/share/GeoIP&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# # 下载GeoIP2数据库（需要Nginx支持geoip2模块）&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# wget -P /usr/share/GeoIP https://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-ASN.mmdb&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# wget -P /usr/share/GeoIP https://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-Country.mmdb&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# wget -P /usr/share/GeoIP https://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-City.mmdb&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# ln -s /usr/share/GeoIP/GeoLite2-Country.mmdb /usr/share/GeoIP/GeoLite2-Country.dat&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# 验证数据库文件&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ls -la /usr/share/GeoIP/&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;geoiplookup 8.8.8.8&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id=&#34;3-配置nginx&#34;&gt;3. 配置Nginx&lt;/h3&gt;&#xA;&lt;p&gt;在&lt;code&gt;/etc/nginx/nginx.conf&lt;/code&gt;中添加：&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
