You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加多个Azure NSG规则时端口范围格式报错求助

问题

编写PowerShell脚本从Excel表格批量添加NSG(网络安全组)入站/出站规则时,遇到端口范围格式错误,错误信息如下:

Security rule has invalid Port range. Value provided:
42,53,88,123,135,49152-65535,389,445,5722. Value
should be an integer OR integer range with '-' delimiter. Valid range
0-65535.
| StatusCode: 400 ReasonPhrase: Bad Request ErrorCode: SecurityRuleInvalidPortRange ErrorMessage: Security rule has invalid
Port range. Value provided:
| 42,53,88,123,135,49152-65535,389,445,5722. Value should be an integer OR integer range with '-' delimiter. Valid
range 0-65535.

尝试修改端口为"42"、"53"或'42'、'53'格式,问题仍未解决。

原代码:

# Sign in to your Azure account
Connect-AzAccount
Install-Module -Name ImportExcel -AllowClobber -Scope CurrentUser

$subscription = Read-Host "Enter the Subscription Name or ID"
Set-AzContext -Subscription $subscription

$resourcegroups = $args[0]

$nsgName = "TestNSG"

$nsgObj = Get-AzNetworkSecurityGroup -Name $NSG

$rules = Import-Excel -Path ./home/lokesh/NSG_Rules.xlsx

foreach ($rule in $rules) {
  $Params = @{
    'Name'                     = $rule.Name
    'Protocol'                 = $rule.Protocol
    'Direction'                = $rule.Direction
    'Priority'                 = $rule.Priority
    'SourceAddressPrefix'      = $rule.SourceAddressPrefix
    'SourcePortRange'          = $rule.SourcePortRange
    'DestinationAddressPrefix' = $rule.DestinationAddressPrefix
    'DestinationPortRange'     = $rule.DestinationPortRange
    'Access'                   = $rule.Access
    'Description'              = $rule.Description
  }
  $nsgObj | Add-AzNetworkSecurityRuleConfig @Params | Set-AzNetworkSecurityGroup
}
解决方案

问题根源是Azure的Add-AzNetworkSecurityRuleConfig cmdlet要求端口范围参数(SourcePortRange/DestinationPortRange)必须是数组类型,但从Excel导入的多端口是逗号分隔的字符串格式,直接传入会被识别为单个无效的端口值。

修复步骤:

  • 对Excel读取的端口字符串进行拆分,转为字符串数组
  • 确保每个端口/端口范围符合格式要求(单个整数或起始-结束格式)

修改后的代码:

# Sign in to your Azure account
Connect-AzAccount
# 仅在未安装时导入模块,避免重复执行
if (-not (Get-Module -ListAvailable -Name ImportExcel)) {
    Install-Module -Name ImportExcel -AllowClobber -Scope CurrentUser -Force
}

$subscription = Read-Host "Enter the Subscription Name or ID"
Set-AzContext -Subscription $subscription

$nsgName = "TestNSG"
$nsgObj = Get-AzNetworkSecurityGroup -Name $nsgName

$rules = Import-Excel -Path ./home/lokesh/NSG_Rules.xlsx

foreach ($rule in $rules) {
    # 处理源端口范围:拆分字符串为数组并去除多余空格
    $sourcePorts = if ($rule.SourcePortRange) {
        $rule.SourcePortRange -split ',' | ForEach-Object { $_.Trim() }
    } else {
        $null
    }

    # 处理目标端口范围:拆分字符串为数组并去除多余空格
    $destinationPorts = if ($rule.DestinationPortRange) {
        $rule.DestinationPortRange -split ',' | ForEach-Object { $_.Trim() }
    } else {
        $null
    }

    $Params = @{
        'Name'                     = $rule.Name
        'Protocol'                 = $rule.Protocol
        'Direction'                = $rule.Direction
        'Priority'                 = $rule.Priority
        'SourceAddressPrefix'      = $rule.SourceAddressPrefix
        'SourcePortRange'          = $sourcePorts
        'DestinationAddressPrefix' = $rule.DestinationAddressPrefix
        'DestinationPortRange'     = $destinationPorts
        'Access'                   = $rule.Access
        'Description'              = $rule.Description
    }
    # 先累积规则配置,避免循环内重复调用Set-AzNetworkSecurityGroup
    $nsgObj = $nsgObj | Add-AzNetworkSecurityRuleConfig @Params
}
# 最后一次性提交所有规则变更
$nsgObj | Set-AzNetworkSecurityGroup

额外优化点:

  1. 增加模块存在性检查,避免每次执行都尝试安装ImportExcel
  2. 将Set-AzNetworkSecurityGroup移到循环外,减少API调用次数,提升执行效率

内容的提问来源于stack exchange,提问作者Lokesh M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 04:57:35