Obtain the client IP address on your origin server after you enable CDN acceleration.
Methods
After acceleration is enabled, your origin server obtains the IP address of the CDN node instead of the client IP address. To obtain the client IP address on your origin server, use either of the following methods:
Install the
toakernel module on your origin Linux server. This method is simple and completely transparent to your applications: you obtain the real client IP address without modifying the applications on the origin server. Thetoamodule supports specific Linux versions only.Proxy Protocol has no requirement for the system kernel, but you must modify your applications accordingly. The protocol carries the client IP address in a text string that your application parses. Nginx and HAProxy already support Proxy Protocol.
Install the toa module
If your origin server runs one of the Linux versions listed in the following table, install the RPM package of the toa module to obtain the client IP address.
| Supported Linux versions | RPM package download |
| CentOS 6.5 | CentOS 6.5 RPM |
| CentOS 6.9 | CentOS 6.9 RPM |
| CentOS 7.0 | CentOS 7.0 RPM |
| CentOS 7.1 | CentOS 7.1 RPM |
| CentOS 7.2 | CentOS 7.2 RPM |
| CentOS 7.3 | CentOS 7.3 RPM |
| CentOS 7.4 | CentOS 7.4 RPM |
| CentOS 7.5 | CentOS 7.5 RPM |
| alicdn.alios7 | alicdn.alios7 RPM |
Install the corresponding package version by running the
rpmcommand.rpm -ivh tcp-toa-1.2.7-alicdn.alios7.x86_64.rpmPreparing... ################################# [100%] Updating / installing... 1:tcp-toa-1.2.7-alicdn.alios7 ################################# [100%]Start the
toamodule.service tcp_toa start[Starting tcp_toa]: Checking installed modules... tcp_toa not installed. Checking module files... [OK] Installing tcp_toa... [OK]Check the running status of the
toamodule.lsmod | grep toatcp_toa 12916 0Stop the
toamodule.service tcp_toa stop[Stopping tcp_toa]: Checking installed modules... tcp_toa installed. Checking installed tcp_toa... [OK] Uninstalling tcp_toa... [OK]You can uninstall the
toamodule by runningrpm -e tcp-toa.rpm -e tcp-toa[Stopping tcp_toa]: Checking installed modules... tcp_toa installed. Checking installed tcp_toa... [OK] Uninstalling tcp_toa... [OK]
Use Proxy Protocol
To obtain the client IP address by using Proxy Protocol, you must configure the feature in the console. After the feature is enabled, the CDN node establishes a TCP connection with the origin server and transmits the Proxy Protocol text before it transmits the first user payload.
To configure Nginx to accept Proxy Protocol, add the proxy_protocol parameter after the listen directive in the server block. For more information, see Accepting the PROXY Protocol.
http {
#...
server {
listen 80 proxy_protocol;
listen 443 ssl proxy_protocol;
#...
}
}For other applications that support Proxy Protocol, see Proxy Protocol.
For applications that do not support Proxy Protocol, read the Proxy Protocol text line after the TCP connection is established and parse the string to obtain the client IP address. The following example shows the string:
PROXY TCP4 10.10.10.10 192.168.0.1 12345 80\r\nWhen you parse the string, read the line up to the \n character, and then parse the line based on the protocol. The fields are defined as follows:
PROXY_STRING + single space + INET_PROTOCOL + single space + CLIENT_IP + single space + PROXY_IP + single space + CLIENT_PORT + single space + PROXY_PORT + "\r\n"Compared with the preceding format, the actual Proxy Protocol text line may contain a globally unique ID before \r\n. This ID is used for end-to-end monitoring. You can ignore the ID if you do not need it.
"id"="xxxx"