{"id":131,"date":"2014-04-30T11:11:56","date_gmt":"2014-04-30T16:11:56","guid":{"rendered":"http:\/\/etapien.com\/guides\/?p=131"},"modified":"2020-08-24T14:22:36","modified_gmt":"2020-08-24T19:22:36","slug":"nginx-allow-access-certain-ips","status":"publish","type":"post","link":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/","title":{"rendered":"NGINX &#8211; Allow access only to certain IPs"},"content":{"rendered":"<p><span style=\"color: #555555;\">Nginx has a nice\u00a0module that not many people know about, it basically enables us to\u00a0allow or deny access to directories served by the webserver. The module is named<\/span><em style=\"color: #555555;\">\u00a0<\/em><em style=\"color: #555555;\"><strong>ngx_http_access_module<\/strong><\/em><span style=\"color: #555555;\">\u00a0to allow or deny access to IP address. The syntax looks like this:<\/span><\/p>\n<blockquote><p>location \/ {<br \/>\ndeny 192.168.1.1;<br \/>\nallow 192.168.1.0\/24;<br \/>\nallow 10.1.1.0\/16;<br \/>\nallow 2001:0db8::\/32;<br \/>\ndeny all;<br \/>\n}<\/p><\/blockquote>\n<p style=\"color: #555555;\">The rules are checked in sequence from top to bottom until the first match is found. In this particular\u00a0example subnets 10.1.1.0\/16 and 192.168.1.0\/24 are allowed with the exception of 192.168.1.1.<\/p>\n<p style=\"color: #555555;\"><span style=\"line-height: 1.714285714; font-size: 1rem;\">IPv6 range 2001:0db8::\/32 is also allowed, rest of the world is denied access.<\/span><\/p>\n<p style=\"color: #555555;\"><strong style=\"line-height: 1.714285714; font-size: 1rem;\">So, how to use this to secure your site?<\/strong><\/p>\n<p>Your access list should be included in the\u00a0<em><strong>nginx.conf<\/strong><\/em>\u00a0file but you should never add the IP directly into that file, instead you should create a blocklist file with all the IP\u2019s that I want to block or allow and include this file into the nginx.conf file.<\/p>\n<p>That way you can add the file without being root and the file is checked every time a user tries to access the website.<\/p>\n<p>Here it goes, first of we need to edit the\u00a0<em><strong>nginx.conf<\/strong><\/em>\u00a0file once and for all.<\/p>\n<blockquote><p>nano \/etc\/nginx\/nginx.conf<\/p><\/blockquote>\n<p><span style=\"color: #555555;\">\u00a0Find the\u00a0<\/span><em style=\"color: #555555;\"><strong>http<\/strong>\u00a0<\/em><span style=\"color: #555555;\">sectionand add the following lines inside that block<\/span><\/p>\n<blockquote><p>### Include a blocklist file<br \/>\ninclude \/home\/mikho\/nginx-blockips-inthisfile.conf;<\/p><\/blockquote>\n<p style=\"color: #555555;\">Save and exit with<em><strong>\u00a0Ctrl+X<\/strong><\/em><\/p>\n<p style=\"color: #555555;\">Time to create the include file itself.<\/p>\n<blockquote>\n<p style=\"color: #555555;\">nano \/home\/mikho\/nginx-blockips-inthisfile.conf<\/p>\n<\/blockquote>\n<p style=\"color: #555555;\">add IPs as you wish, if there is no explicit deny row, it will allow the connection:<\/p>\n<blockquote>\n<p style=\"color: #555555;\">deny 192.168.1.1;<br \/>\ndeny 192.168.1.2;<br \/>\ndeny 192.168.2.1\/24;<\/p>\n<\/blockquote>\n<p style=\"color: #555555;\">if you want it to work the other way around and deny everyone that is\u00a0<strong>NOT<\/strong>\u00a0explicitly allowed in the file you could add these lines:<\/p>\n<blockquote>\n<p style=\"color: #555555;\"># allow the internal subnet 192.168.1.0\/24<br \/>\nallow 192.168.1.0\/24;<br \/>\n# drop rest of the world<br \/>\ndeny all;<\/p>\n<\/blockquote>\n<p>When you are done, Save and Exit with\u00a0<em><strong>Ctrl+X<\/strong><\/em>.<\/p>\n<p>test the configuration for spelling errors other configuration errors with:<\/p>\n<blockquote><p>\/etc\/init.d\/nginx configtest<\/p><\/blockquote>\n<p style=\"color: #555555;\">If you get an error message, troubleshoot the error and test again until everything is fine.<\/p>\n<p style=\"color: #555555;\">Reload the configuration with:<\/p>\n<blockquote>\n<p style=\"color: #555555;\">\/etc\/init.d\/nginx force-reload<\/p>\n<\/blockquote>\n<p style=\"color: #555555;\">Try it out from different IPs and see the difference.<\/p>\n<h2 style=\"font-weight: 400;\">Customize the HTTP 403 Forbidden Error Message<\/h2>\n<p>&nbsp;<\/p>\n<p style=\"color: #555555;\">The default 403 error page is, well very &#8220;default&#8221; and plain so let&#8217;s create something nicer.<\/p>\n<p style=\"color: #555555;\">create an html file in your webroot folder that we should load when the error occurs, paste this into the file:<\/p>\n<blockquote>\n<p style=\"color: #555555;\">&lt;html&gt;<br \/>\n&lt;head&gt;&lt;title&gt;Error 403 &#8211; Access denied!&lt;\/title&gt;&lt;\/head&gt;<br \/>\n&lt;body&gt;<br \/>\nYou do not have access to this page. There&#8217;s no need to try again.<br \/>\n&lt;\/body&gt;<br \/>\n&lt;\/html&gt;<\/p>\n<\/blockquote>\n<p style=\"color: #555555;\">then edit your Nginx config file and add this<\/p>\n<blockquote>\n<p style=\"color: #555555;\">error_page 403 \/error403.html;<br \/>\nlocation \/error403.html {<br \/>\nallow all;<br \/>\n}<\/p>\n<\/blockquote>\n<p>inside the server block. The example above tells Nginx to display the file error403.html everytime a 403 error occurs. We do need to make the exemption in the configuration file that everyone will be allowed to read this file, otherwise a default 403 error page would be displayed.<\/p>\n<p>Now\u00a0you know how to easily block access to your website and only allow a few selected IPs.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nginx has a nice\u00a0module that not many people know about, it basically enables us to\u00a0allow or deny access to directories served by the webserver. The module is named\u00a0ngx_http_access_module\u00a0to allow or deny access to IP address. The syntax looks like this: location \/ { deny 192.168.1.1; allow 192.168.1.0\/24; allow 10.1.1.0\/16; allow 2001:0db8::\/32; deny all; } The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>NGINX - Allow access only to certain IPs - Tech Howtos<\/title>\n<meta name=\"description\" content=\"block or allow access per ip to nginx\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NGINX - Allow access only to certain IPs - Tech Howtos\" \/>\n<meta property=\"og:description\" content=\"block or allow access per ip to nginx\" \/>\n<meta property=\"og:url\" content=\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/\" \/>\n<meta property=\"og:site_name\" content=\"Tech Howtos\" \/>\n<meta property=\"article:published_time\" content=\"2014-04-30T16:11:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-08-24T19:22:36+00:00\" \/>\n<meta name=\"author\" content=\"Etapien\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Etapien\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/\",\"url\":\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/\",\"name\":\"NGINX - Allow access only to certain IPs - Tech Howtos\",\"isPartOf\":{\"@id\":\"https:\/\/etapien.com\/guides\/#website\"},\"datePublished\":\"2014-04-30T16:11:56+00:00\",\"dateModified\":\"2020-08-24T19:22:36+00:00\",\"author\":{\"@id\":\"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424\"},\"description\":\"block or allow access per ip to nginx\",\"breadcrumb\":{\"@id\":\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/etapien.com\/guides\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NGINX &#8211; Allow access only to certain IPs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/etapien.com\/guides\/#website\",\"url\":\"https:\/\/etapien.com\/guides\/\",\"name\":\"Tech Howtos\",\"description\":\"Tech related useful howtos\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/etapien.com\/guides\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424\",\"name\":\"Etapien\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/etapien.com\/guides\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g\",\"caption\":\"Etapien\"},\"url\":\"https:\/\/etapien.com\/guides\/author\/Etapien\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NGINX - Allow access only to certain IPs - Tech Howtos","description":"block or allow access per ip to nginx","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/","og_locale":"en_US","og_type":"article","og_title":"NGINX - Allow access only to certain IPs - Tech Howtos","og_description":"block or allow access per ip to nginx","og_url":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/","og_site_name":"Tech Howtos","article_published_time":"2014-04-30T16:11:56+00:00","article_modified_time":"2020-08-24T19:22:36+00:00","author":"Etapien","twitter_misc":{"Written by":"Etapien","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/","url":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/","name":"NGINX - Allow access only to certain IPs - Tech Howtos","isPartOf":{"@id":"https:\/\/etapien.com\/guides\/#website"},"datePublished":"2014-04-30T16:11:56+00:00","dateModified":"2020-08-24T19:22:36+00:00","author":{"@id":"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424"},"description":"block or allow access per ip to nginx","breadcrumb":{"@id":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/etapien.com\/guides\/nginx-allow-access-certain-ips\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/etapien.com\/guides\/"},{"@type":"ListItem","position":2,"name":"NGINX &#8211; Allow access only to certain IPs"}]},{"@type":"WebSite","@id":"https:\/\/etapien.com\/guides\/#website","url":"https:\/\/etapien.com\/guides\/","name":"Tech Howtos","description":"Tech related useful howtos","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/etapien.com\/guides\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424","name":"Etapien","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/etapien.com\/guides\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g","caption":"Etapien"},"url":"https:\/\/etapien.com\/guides\/author\/Etapien\/"}]}},"_links":{"self":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts\/131"}],"collection":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/comments?post=131"}],"version-history":[{"count":1,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts\/131\/revisions"}],"predecessor-version":[{"id":132,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts\/131\/revisions\/132"}],"wp:attachment":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/media?parent=131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/categories?post=131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/tags?post=131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}