Hiển thị các bài đăng có nhãn IIS. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn IIS. Hiển thị tất cả bài đăng

Thứ Hai, 4 tháng 8, 2025

[IIS][ASP.NET] Cách TroubleShooting nguyên nhân gây lỗi crash w3wp.exe (crash pool) trên window

Thực trạng : 1 website chỉ bị lỗi sau khi đăng nhập vào trang quản trị. Mỗi khi đăng nhập vào quản trị thì sẽ làm crash pool (web 503 hoặc treo hoàn toàn website)

Kiểm tra

Tham khảo : https://learn.microsoft.com/en-us/troubleshoot/developer/webapps/iis/site-behavior-performance/process-termination-crash

Cách 1 : sử dụng Event Viewer Log

Kiểm tra Event Viewer -> System sẽ có log tương tư

A process serving application pool '****' suffered a fatal communication error with the Windows Process Activation Service. The process id was '21720'. The data field contains the error number.

Với lỗi này. process w3wp.exe đã bị crash. và để kiểm tra nguyên nhân crash thì xem trong Event Viewer -> Application , chọn Filter :

- Event Source : Application Error

- Event ID : 1000

Khi đó sẽ xem được lỗi crash process chi tiết (cách này áp dụng được cho toàn bộ các loại ứng dụng trên window)


Tới đây xác định được lỗi và tiến hành tìm hiểu theo log trên.


Cách 12 : sử dụng Debug Diagnostic Tool 

- Kiểm tra lỗi crash bằng Tool và Export Dump file :

https://learn.microsoft.com/en-us/troubleshoot/developer/webapps/iis/site-behavior-performance/process-termination-crash#debug-diagnostic-tool


- Phân tích kết quả từ File dump export ở bước trên :

https://learn.microsoft.com/en-us/troubleshoot/developer/webapps/iis/site-behavior-performance/process-termination-crash#how-to-perform-data-analysis




 

Với lỗi crash w3wp.exe và module pcre.dll trên server chạy Plesk thì là do ModSecurity. Cần tắt đi hoàn toàn ModSecurity trên site. Để chế độ "Detection only" vẫn bị lỗi

Tham khảo : https://stackoverflow.com/questions/79686656/iis-asp-net-umbraco-exception-on-on-w3wp-exe-and-pcre-dll

 




Thứ Hai, 31 tháng 3, 2025

[ASP.NET][IIS] Illegal characters in path trong ASP.NET

Lỗi “Illegal characters in path” là do truy cập vào url có chứa ký tự đặc biệt. mặc định .net sẽ không thẻ xử lý các link có ký tự đặc biệt và sẽ báo lỗi này.

Đề xử lý có 2 hướng:


C1 - xử lý trong code : trên code website sẽ thêm phần xử lý url trước khi thực thi đề tránh lỗi. tham khảo stackoverflow : https://stackoverflow.com/questions/2435894/how-do-i-check-for-illegal-characters-in-a-path


C2- Xử lý chặn trực tiếp các link chứa ký tự đặc biệt.


VD : Chắn link có ký tự “|” vd như link http://abc.com/gfd|gfd .


Thực hiện chặn bằng request filtering trong file web.config hoặc tạo tay trên IIS (cũng sẽ ghi vào web.confg)


<system.webServer>

    <security>

        <requestFiltering>

            <denyUrlSequences>

                <add sequence="|" />

            </denyUrlSequences>

        </requestFiltering>

    </security>

</system.webServer>


Thực hiện trên IIS thì vào website -> Requets Filtering -> tab URL chọn Deny Sequences và thêm ký tự muốn chặn vào 

Thứ Bảy, 11 tháng 5, 2024

[ASP.NET][IIS] Bật Fusion Log, chuẩn đoán lỗi chuyên sâu IIS

 Mở regedit và vào path sau

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
Tạo các key sau
LogFailures set value to 1 (DWORD)
LogResourceBinds set value to 1 (DWORD)
LogPath (String) set value to C:\FusionLog\

Thứ Năm, 14 tháng 10, 2021

[ASP.NET][IIS] Error CS0016: Could not write to output file ....

 Lỗi liên quan tới compiler csc của .NET Framework

Compiler Error Message: CS0016: Could not write to output file 'c:\Windows\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\root\3ab7b770\3750c939\en-US\App_GlobalResources.l8frv07t.resources.dll' -- 'Access is denied. '


Với lỗi này có 2 nguyên nhân

1. Thư mục Temp của ASP.NET không có quyền write, cần kiểm tra lại
2. Thư mục C:\Windows\Temp không có quyền write. Cần kiểm tra lại

Nếu đã đảm bảo 2 yếu tố trên mà vẫn lỗi thì có thể áp dụng.

thêm vào web.config :

<identity impersonate="true" userName="devdomain\youruser" password="yourpassword" />

Sau đó cấp full quyền cho user devdomain\yourusername vào thư muc Temp của ASP.NET

Thứ Tư, 4 tháng 8, 2021

[ASP.NET] kiểm tra , chuẩn đoán lỗi net::ERR_HTTP2_PROTOCOL_ERROR

 Với lỗi net::ERR_HTTP2_PROTOCOL_ERROR  xảy ra với ajax jquery XMLHttpRequest  thông thường nguyên nhân không liên quan tới HTTP2. 

Nguyên nhân chính dẫn tới lỗi này thường là do lỗi khi thực thi code trên website, hoặc do bị reset connection.

Nếu disable HTTP2 và để chạy HTTP1.1 mà theo dõi có phát sinh lỗi net::ERR_CONNECTION_RESET  thì nguyên nhân chính sẽ là do thời điểm đó kết nối bị mất không có phản hồi từ server dẫn tới code ajax timeout không nhận được responsed và trả về lỗi net::ERR_HTTP2_PROTOCOL_ERROR


Các bước để chuẩn đoán :

- Kiểm tra window eventlog "Application" xem có lỗi gì liên quan website hay không

- Kiểm tra window eventlog "System" xem có thông tin liên quan tới lỗi application pool của website hay không (Source WAS). nếu có log như sau thì đây là nguyên nhân

A process serving application pool 'xxx' suffered a fatal communication error with the Windows Process Activation Service. The process id was 'yyy'. The data field contains the error number.

Để kiểm tra chi tiết hơn thì cần sử dụng công cụ DebugDiag, chọn mục "Crash" -> "A Special IIS Web Application pool". Sau đó chọn pool để theo dõi. Khi nào có dump file thì dùng DebugDiag Analysis để mở lên xem chi tiết . Ví dụ như ảnh dưới



Tham khảo thêm

31623G9043 : lỗi do thiếu quyền ghi log file

39VTD27590 : Lỗi code gây crash pool.

Thứ Năm, 14 tháng 5, 2020

The specified path, file name, or both are too long. The fully qualified file name must be less than 260 characters, and the directory name must be less than 248

The specified path, file name, or both are too long. The fully qualified file name must be less than 260 characters, and the directory name must be less than 248 characters

C1 : mở regedit
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem
chọn DWORD : LongPathsEnabled set value 1

C2: Mở Policy gpedit.msc
Computer Configuration > Administrative Templates > System > Filesystem
"Enable win32 long paths" --> Enable

IIS/WEB site
system.web/httpRuntime/maxURLLength : mặc định 260
-> set tăng lên

<system.web>
<httpRuntime maxUrlLength="500" />
</system.web>


Trên application manifest cần khai báo thêm longPathAware

<application xmlns="urn:schemas-microsoft-com:asm.v3">
    <windowsSettings xmlns:ws2="http://schemas.microsoft.com/SMI/2016/WindowsSettings">
        <ws2:longPathAware>true</ws2:longPathAware>
    </windowsSettings>
</application>

https://docs.microsoft.com/vi-vn/windows/win32/fileio/naming-a-file?redirectedfrom=MSDN#maximum-path-length-limitation

Thứ Hai, 10 tháng 6, 2019

[ASP][IIS] - Blocked a frame with origin from accessing a cross-origin frame.

Blocked a frame with origin "http://hcmier.edu.vn" from accessing a cross-origin frame. 

Thường bị khi xài ckeditor. Lỗi này xảy ra khi truy cập trang admin có www mà khi mở ckeditor lại không có www.

VD: link admin là : http://www.hcmier.edu.vn/vn/wcms/UserLogin.asp
khi mở ckeditor thì chạy sang link http://hcmier.edu.vn thì sẽ lỗi


==> Cần login vào theo link không www  : http://hcmier.edu.vn/vn/wcms/UserLogin.asp

27U6374938 

Thứ Hai, 7 tháng 1, 2019

[ASP.NET][DevExpress] Exception Details: System.NotSupportedException: Collection is read-only.

Code sử dụng devexpress, chức năng upload file ảnh bị lỗi, có thông tin log error như sau
Exception Details: System.NotSupportedException: Collection is read-only.

=> Vào ISAPI Filter của site trên IIS remove 2 khai báo liên quan helicon rewrite

[ASP.NET][IIS] HttpException (0x80004005): This server variable cannot be modified during request execution

Mô tả, trang admin đăng nhập báo lỗi [HttpException (0x80004005): This server variable cannot be modified during request execution.]

Sử dụng 2 trang, trang admin (đăng nhập) gọi qua 1 trang api (web service) để chứng thực và xảy ra lỗi trên.

Nguyên nhân là do xung đột SF_NOTIFY_AUTHENTICATION event của ISAP Filter và Application_BeginRequest event trong file global.asax của source code.
(https://support.microsoft.com/en-ca/help/2605401/a-system-web-httpexception-occurs-in-internet-information-services-7-0)

=> xử lý 1 trong các cách sau

1. Site site sang pool classsic (nếu Site code tương thích)

2. phải thay đổi code

3. Site bắt buộc chạy pool integrated thì có thể remove các khai báo trong mục ISAP Filter của Site trên IIS

Thứ Sáu, 30 tháng 5, 2014

[Wordpress][IIS] Rewrite URL Wordpress Với Web.config Trên IIS7

Website wordpress chạy trên IIS7 không nhận link rewrite có thể xử lý bằng cách cấu hình rewrite trong web.config thay cho .htaccess
Yêu cầu IIS7 đã install URL Rewrite Module. Set rule rewrite trong web.config như sau

Chủ Nhật, 13 tháng 4, 2014

[IIS] How To Configure PassivePortRange In IIS

How to add PassivePortRange in IIS and firewall exception fot Microsoft FTP service (MSFTPSVC) in windows server ?

Applicable to : Windows 2000 Server with IIS5
Windows 2003 Server with IIS6
Windows 2008 Server with IIS7
To work FTP passive connection properly we have to do two things
A) Add Passive port range in IIS
B) Add firewall exception in windows firewall

For Windows 2000 Server

A) Add Passive port range in IIS
Configure PassivePortRange via Registry Editor
1. Start Registry Editor (Regedt32.exe).
2. Locate the following registry key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Msftpsvc\Parameters\
3. Add a value named “PassivePortRange” (without the quotation marks) of type REG_SZ.
4. Close Registry Editor.
5. Restart the FTP service.

Note: The range that FTP will validate is from 5001 to 65535.
B) Add firewall exception in windows firewall
To add a range of ports to Windows Firewall from the Command Line
1. Click Start, click Run, type cmd, and then click OK.
2. Type in the following where the range is specified in ( ) and the name of the firewall entry is in ” “.
FOR /L %I IN (5500,1,5701) DO netsh firewall add portopening TCP %I "Passive FTP"%I
3. Each port in the range will be added with an “OK” confirmation.

Or you can manually add the port exception as follows.
1. Click Start >> Run >> firewall.cpl ( Hit enter) , and select the Exceptions tab.
2. Click the Add Port button.
3. Enter a Name for the Exception and the first number in the port range.
4. Click TCP if not already selected and click OK.
5. Repeat for each port in the range – for large ranges see the end of the document.
6. Enable the Windows Firewall on the General Tab.

For Windows 2003 Server

A) Add Passive port range in IIS
a) To Enable Direct Metabase Edit
1. Open the IIS Microsoft Management Console (MMC).
2. Right-click on the Local Computer node.
3. Select Properties.
4. Make sure the Enable Direct Metabase Edit checkbox is checked.

b) Configure PassivePortRange via ADSUTIL script
1. Click Start, click Run, type cmd, and then click OK.
2. Type cd Inetpub\AdminScripts and then press ENTER.
3. Type the following command from a command prompt.
adsutil.vbs set /MSFTPSVC/PassivePortRange “5500-5700″
4. Restart the FTP service.

You’ll see the following output, when you configure via ADSUTIL script:
Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001.
All rights reserved.PassivePortRange : (STRING) “5500-5700″
B) Add firewall exception in windows firewall
To add a range of ports to Windows Firewall from the Command Line
1. Click Start, click Run, type cmd, and then click OK.
2. Type in the following where the range is specified in ( ) and the name of the firewall entry is in ” “.
FOR /L %I IN (5500,1,5701) DO netsh firewall add portopening TCP %I "Passive FTP"%I
3. Each port in the range will be added with an “OK” confirmation.

Or you can manually add the port exception as follows.
1. Click Start >> Run >> firewall.cpl ( Hit enter) , and select the Exceptions tab.
2. Click the Add Port button.
3. Enter a Name for the Exception and the first number in the port range.
4. Click TCP if not already selected and click OK.
5. Repeat for each port in the range – for large ranges see the end of the document.
6. Enable the Windows Firewall on the General Tab.

For Windows 2008 Server


A) Add Passive port range  in IIS

1. Go to IIS 7.0 Manager. In the Connections pane, click the server-level node in the tree.
2.  Double-click the FTP Firewall Support icon in the list of features.
3. Enter a range of values for the Data Channel Port Range.
4. Once you have entered the port range for your FTP service, click Apply in the Actions pane to save your configuration settings.

Notes:
1. The valid range for ports is 1024 through 65535. (Ports from 1 through 1023 are reserved for use by system services.)
2. You can enter a special port range of “0-0″ to configure the FTP server to use the Windows TCP/IP dynamic port range. The default dynamic port range in windows 2008 server is from 49152 to 65535.

You can view this details by issuing the folowing command in the server.
C:\Users\Administrator>netsh int ipv4 show dynamicport tcp
3. For additional information, please see the following Microsoft Knowledge Base articles:
* 929851 – http://support.microsoft.com/kb/929851/
4. This port range will need to be added to the allowed settings for your firewall server.
To configure the external IPv4 Address for a Specific FTP Site

1. Go to IIS 7.0 Manager. In the Connections pane, click the FTP site that you created earlier in the tree, Double-click the FTP Firewall Support icon in the list of features.
2. Enter the IPv4 address of the external-facing address of your firewall server for the External IP Address of Firewall setting.
3. Once you have entered the external IPv4 address for your firewall server, click Apply in the Actions pane to save your configuration settings.

B. Add firewall exception in windows firewall
To add a range of ports to Windows Firewall from the Command Line
1. Click Start, click Run, type cmd, and then click OK.
2. Type in the following where the range is specified in ( ) and the name of the firewall entry is in ” “.

3.  FOR /L %I IN (49152,1,65535) DO netsh advfirewall firewall add rule name="Passiveport"%I dir=out action=allow protocol=TCP localport=%I
4. Each port in the range will be added with an “OK” confirmation.
The command to add individual port in exception is pasting below.
C:\Users\Administrator>netsh advfirewall firewall add rule name="OpenPort65535" dir=out action=allow protocol=TCP localport=65535
Reference : http://support.microsoft.com/kb/555022
http://learn.iis.net/page.aspx/309/configuring-ftp-firewall-settings/

Thứ Bảy, 12 tháng 4, 2014

[IIS] IIS7 Custom Error not working

II7 customError not working

chinh trong web.config
<httpErrors errorMode="Custom" existingResponse="Replace">

chinh trong IIS -> Configuration Editor (trong cụm Management) -> chỉnh system.webServer/httpErrors

Thứ Tư, 9 tháng 4, 2014

[ASP.NET][IIS] SesstionState : Session state can only be used when enableSessionState is set to true

Error
Session state can only be used when enableSessionState is set to true, either in a configuration file or in the Page directive. Please also make sure that System.Web.SessionStateModule or a custom session state module is included in the <configuration><system.web><httpModules> section in the application configuration.

You need to :

1. include a <pages... > attribute in web.config :

<pages enableSessionState = "true" />

*or*

2. enable SessionState in the <%@ Page ...%> directive in your page :

<%@ Page enableSessionState = "true" %>

Also, the System.Web.SessionStateModule should exist in your
<httpModules> section in the application configuration.

Hoặc:
Vào IIS -> site -> modules -> session bỏ check mục “Invoke only for request to ASP.NET applications or managed handler”

Thứ Năm, 3 tháng 4, 2014

[IIS] Import / Export application pool/website config

To Export the Application Pools on IIS 7 :
%windir%\system32\inetsrv\appcmd list apppool /config /xml > c:\apppools.xml
To import the Application Pools:
%windir%\system32\inetsrv\appcmd add apppool /in < c:\apppools.xml
To Export all you’re website:
%windir%\system32\inetsrv\appcmd list site /config /xml > c:\sites.xml
This will export all the websites on you’re webserver, therefor you need to edit the sites.xml and remove the websites that you do not need to import for example:
To Import the website:
%windir%\system32\inetsrv\appcmd add site /in < c:\sites.xml
It’s also possible to export a single website or application pool all you need to do is add the name of the Application Pool or Website to the command line:
To export/import a single application pool:
%windir%\system32\inetsrv\appcmd list apppool “MyAppPool” /config /xml > c:\myapppool.xml
Import:
%windir%\system32\inetsrv\appcmd add apppool /in < c:\myapppool.xml
To export/import a single website:
%windir%\system32\inetsrv\appcmd list site “MyWebsite” /config /xml > c:\mywebsite.xml
Import:
%windir%\system32\inetsrv\appcmd add site /in < c:\mywebsite.xml
http://www.microsoftpro.nl/2011/01/27/exporting-and-importing-sites-and-app-pools-from-iis-7-and-7-5/