Ffile2fix
Sign in Get started

How to fix "AH01630: client denied by server configuration"

[authz_core:error] [pid 12345] [client 203.0.113.5:51234] AH01630: client denied by server configuration: /home/user/public_html/index.php

Apache 2.4 checked its access rules and none of them allowed this request, so it returned 403 Forbidden. It usually happens after moving to Apache 2.4 with old 2.2-style Order/Allow rules, or when a Directory block for the site root has no Require all granted.

Also appears as: AH01630: client denied by server configuration: /var/www/html/ · AH01797: client denied by server configuration: /home/user/public_html/wp-config.php · Forbidden. You don't have permission to access this resource. · client denied by server configuration: proxy:http://127.0.0.1:8080/

Common causes

  • The site's <Directory> block lacks Require all granted (Apache 2.4 denies by default outside /var/www)
  • Old Apache 2.2 Order allow,deny / Allow from all syntax without mod_access_compat
  • A Require ip or Require host rule that excludes the visitor
  • An .htaccess file with Require all denied or Deny from all in a parent folder
  • A <Files> or <FilesMatch> rule blocking the requested file type
  • The DocumentRoot was moved but the Directory block still points to the old path

How to fix it

  1. Find which rule applies. The path in the log line tells you which file or folder was denied. Search the vhost and every .htaccess from that folder up to the root for Require, Deny and Order lines.
  2. Grant access to the site root. In the virtual host, add a <Directory /home/user/public_html> block with Require all granted. Run sudo apachectl configtest and reload Apache.
  3. Convert 2.2 rules to 2.4 syntax. Replace Order allow,deny plus Allow from all with Require all granted. Replace Deny from all with Require all denied. Do not mix the two styles in one block.
  4. Check IP restrictions. If you use Require ip 198.51.100.10, make sure your current IP is on the list. Behind a proxy or CDN, Apache sees the proxy IP unless mod_remoteip is set up.
  5. Confirm the block is intentional. AH01630 on files like wp-config.php, .env or .git is often a correct security rule. Only change rules for paths that should be public.

Apache 2.4 Directory block for a site root

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /home/user/public_html
    <Directory /home/user/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

How to stop it happening again

  • Use only Apache 2.4 Require syntax
  • Update Directory blocks whenever you change DocumentRoot
  • Set up mod_remoteip when behind a proxy or CDN
  • Keep deny rules for sensitive files and test them on purpose

Frequently asked questions

Why did this start after upgrading Apache?

Apache 2.4 replaced Order/Allow/Deny with Require. Old rules only work if mod_access_compat is loaded, and mixing styles gives unexpected denials.

Is AH01630 always a problem?

No. Bots probing for files like .env or xmlrpc.php trigger it when your deny rules work correctly. Only fix it for URLs real visitors need.

Is it a file permission issue?

No. File permission problems log 'Permission denied' with error code 13. AH01630 is purely Apache's access rules.