You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure CLI或Terraform创建指定目标VM的Azure LB入站NAT规则?

Azure Load Balancer入站NAT规则:CLI与Terraform实现门户一致配置

完全可以通过Azure CLI或Terraform实现和Azure门户完全一致的入站NAT规则配置——门户中选择目标VM的操作,本质是自动将NAT规则关联到VM对应的网络接口IP配置,CLI和Terraform只需直接指定该关联关系即可。

Azure CLI实现

使用az network lb inbound-nat-rule create命令,通过--backend-ip-config参数直接指定目标VM的网络接口及IP配置(格式为<网卡名称>/<IP配置名称>),无需额外步骤。示例命令:

az network lb inbound-nat-rule create \
  --resource-group your-resource-group \
  --lb-name your-loadbalancer \
  --name ssh-nat-rule \
  --frontend-ip-name your-frontend-ip \
  --protocol TCP \
  --frontend-port 2222 \
  --backend-port 22 \
  --backend-ip-config your-vm-nic/your-vm-ip-config

注:若VM使用默认网卡配置,IP配置名称通常为ipconfig1,可通过az network nic show命令查看。

Terraform实现

无需单独创建绑定资源,直接在azurerm_lb_inbound_nat_rule资源中通过backend_ip_configuration_id参数引用VM网络接口的IP配置ID即可。示例代码:

# 定义资源组
resource "azurerm_resource_group" "example" {
  name     = "example-resources"
  location = "East US"
}

# 定义子网与虚拟网络
resource "azurerm_virtual_network" "example" {
  name                = "example-network"
  address_space       = ["10.0.0.0/16"]
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
}

resource "azurerm_subnet" "example" {
  name                 = "example-subnet"
  resource_group_name  = azurerm_resource_group.example.name
  virtual_network_name = azurerm_virtual_network.example.name
  address_prefixes     = ["10.0.1.0/24"]
}

# 定义VM的网络接口
resource "azurerm_network_interface" "vm_nic" {
  name                = "example-vm-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
  }
}

# 定义负载均衡器
resource "azurerm_lb" "example" {
  name                = "example-lb"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  frontend_ip_configuration {
    name                 = "example-frontend-ip"
    public_ip_address_id = azurerm_public_ip.example.id
  }
}

resource "azurerm_public_ip" "example" {
  name                = "example-pip"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  allocation_method   = "Static"
}

# 定义入站NAT规则,直接关联VM网卡IP配置
resource "azurerm_lb_inbound_nat_rule" "ssh_rule" {
  name                          = "ssh-nat-rule"
  resource_group_name           = azurerm_resource_group.example.name
  loadbalancer_id               = azurerm_lb.example.id
  frontend_ip_configuration_id  = azurerm_lb.example.frontend_ip_configuration[0].id

  protocol                      = "Tcp"
  frontend_port                 = 2222
  backend_port                  = 22
  backend_ip_configuration_id   = azurerm_network_interface.vm_nic.ip_configuration[0].id
}

注:若之前尝试单独绑定未生效,通常是因为错误使用了非直接关联的资源(如单独的关联资源),直接在NAT规则资源中指定backend_ip_configuration_id才是和门户逻辑一致的正确方式。

内容的提问来源于stack exchange,提问作者Petro Kolosov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 02:46:07