添加Azure NSG规则时遭遇无效地址前缀错误请求解决
解决Azure NSG规则无效地址前缀错误
错误原因
SecurityRuleInvalidAddressPrefix错误源于DestinationAddressPrefix参数的格式问题:你传入了逗号分隔的字符串"10.201.0.5,10.201.2.4",但Azure PowerShell的Add-AzNetworkSecurityRuleConfig cmdlet要求多地址前缀必须以PowerShell数组形式传递,不能用逗号拼接成单一字符串。此外DestinationPortRange使用的普通括号(514, 6514)不符合数组语法规范,需要改用@()定义数组。
修正后的PowerShell命令
Get-AzNetworkSecurityGroup -ResourceGroupName MYRG -Name MYNSG | Add-AzNetworkSecurityRuleConfig -Name AllowSyslog-Outbound -Access Allow -Protocol * -Direction Outbound -Priority 3001 -SourceAddressPrefix 10.200.32.36 -SourcePortRange * -DestinationAddressPrefix @("10.201.0.5","10.201.2.4") -DestinationPortRange @(514, 6514) | Set-AzNetworkSecurityGroup
关键注意点
- 指定多个地址前缀、端口范围时,必须使用
@(值1, 值2)的PowerShell数组语法 - 单个地址或端口可直接传递字符串/数值,无需数组包装
内容的提问来源于stack exchange,提问作者RSW
相关产品推荐
相关产品推荐

