You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible:如何将IP列表添加到Windows防火墙443允许规则?

解决Windows Server 443端口仅允许指定IP访问的Ansible配置问题

问题场景

需要配置Windows Server防火墙,限制443端口仅允许指定IP访问。现有单IP规则可正常运行,但尝试通过列表批量添加IP时,仅最后一个IP生效,规则未正确包含所有指定IP。

错误写法分析

原尝试的loop配置存在两处关键问题:

remoteip: "{{ item.ip | default('any') }}"
state: present
force: yes
loop:
  - "{{ ip_addresses }}"
  • loop中用- "{{ ip_addresses }}"会把整个IP列表作为单个循环项,而非遍历列表中的每个IP条目
  • 由于规则名称固定为Apache Webserver,每次循环(仅执行一次)会覆盖之前的规则配置,最终仅保留最后处理的IP

正确实现方式

方式一:单规则包含所有允许IP(推荐)

利用win_firewall_rule的remoteip参数支持逗号分隔多IP的特性,直接从列表提取所有IP并拼接:

- name: Firewall rule to allow HTTPS from specified IPs
  win_firewall_rule:
    name: Apache Webserver
    localport: 443
    action: allow
    direction: in
    protocol: tcp
    state: present
    enabled: yes
    # 从ip_addresses列表提取所有ip字段,拼接为逗号分隔的字符串
    remoteip: "{{ ip_addresses | map(attribute='ip') | join(',') }}"

方式二:为每个IP创建独立规则

若需要为每个IP单独创建命名规则,需正确遍历ip_addresses列表,使用每个条目的名称和IP:

- name: Create individual HTTPS access rules for specified IPs
  win_firewall_rule:
    name: "{{ item.name }}"
    localport: 443
    action: allow
    direction: in
    protocol: tcp
    state: present
    enabled: yes
    remoteip: "{{ item.ip | default('any') }}"
  # 直接遍历ip_addresses列表,每个item对应一条IP配置
  loop: "{{ ip_addresses }}"

内容的提问来源于stack exchange,提问作者Noob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 14:05:30