You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ARM模板配置Azure Function的ipSecurityRestrictions后,门户Access restriction未开启

Azure Function ARM模板配置IP限制后门户开关未显示为On的问题解决

问题现象

给Azure Function的ARM模板中Microsoft.Web/sites/config节点添加以下IP安全限制配置后:

"ipSecurityRestrictions": [
    {
        "ipAddress": "Any",
        "action": "Deny",
        "priority": 2147483647,
        "name": "Deny all",
        "description": "Deny all access"
    }
],
"ipSecurityRestrictionsDefaultAction": "Deny",

出现以下异常:

  • 门户里Access restriction的开关始终显示为Off状态
  • 点进Access restriction页面,能看到这条拒绝规则已经成功添加
  • 要是在门户手动配完相同规则再导出ARM模板,代码和上面完全一致,但此时开关会显示为On

原因

门户的Access restriction开关状态不是只看ipSecurityRestrictions和ipSecurityRestrictionsDefaultAction这两个配置,UI判定“是否启用限制”的逻辑里,需要存在至少一条允许规则(哪怕默认动作是Deny,只有拒绝规则的话,UI会认为限制没启用)。另外,偶尔也会遇到UI状态同步延迟的情况。

解决办法

1. 添加一条优先级更高的允许规则

如果你的场景需要允许特定IP访问,直接在拒绝规则前加一条允许规则,注意优先级数值要比拒绝规则小(数值越小优先级越高):

"ipSecurityRestrictions": [
    {
        "ipAddress": "你的允许IP/网段",
        "action": "Allow",
        "priority": 1,
        "name": "Allow trusted IP",
        "description": "Allow access from trusted IP range"
    },
    {
        "ipAddress": "Any",
        "action": "Deny",
        "priority": 2147483647,
        "name": "Deny all",
        "description": "Deny all access"
    }
],
"ipSecurityRestrictionsDefaultAction": "Deny",

重新部署模板后,门户的Access restriction开关就会自动变成On,因为现在有了完整的允许+拒绝规则组合,符合UI的启用判定逻辑。

2. 强制触发UI同步

如果确实只需要拒绝所有访问(没有允许规则),可以手动触发UI状态更新:

  • 进入Azure Function的Access restriction页面
  • 给已存在的拒绝规则做个微小修改,比如改一下描述文字
  • 保存修改,此时开关就会切换为On

3. 检查模板API版本

确保Microsoft.Web/sites/config的API版本是2022-03-01或更高,旧版本可能存在UI同步的兼容性问题:

{
    "type": "Microsoft.Web/sites/config",
    "apiVersion": "2022-03-01",
    "name": "[concat(parameters('functionAppName'), '/web')]",
    // 其他配置内容
}

内容的提问来源于stack exchange,提问作者Tommy Selggren

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 22:12:31