使用Azure CLI创建NSG规则时如何传递多个协议值
Azure CLI创建NSG规则时传递多协议参数的正确方法
Azure CLI的az network nsg rule create命令中,--protocol参数不支持一次性传入多个协议值,你尝试的{Tcp,Icmp}或[Tcp, Icmp]格式都不符合命令的参数要求——每个NSG规则只能指定单个协议类型,或者用通配符匹配所有协议。
解决方案1:为每个协议单独创建NSG规则
如果需要分别允许Tcp、Icmp、Udp协议的流量,需逐个创建规则,示例代码如下:
RG="Test-RG" # 创建NSG az network nsg create --name "${RG}-nsg" --location "eastus" -g $RG # 创建允许Tcp流量的规则 az network nsg rule create -g ${RG} --nsg-name "${RG}-nsg" -n ${RG}-nsg-rule-tcp --priority 100 \ --source-address-prefixes '*' --source-port-ranges '*' --destination-address-prefixes '*' \ --destination-port-ranges '*' --access Allow --protocol Tcp --description "Allowing All Tcp Traffic" # 创建允许Icmp流量的规则 az network nsg rule create -g ${RG} --nsg-name "${RG}-nsg" -n ${RG}-nsg-rule-icmp --priority 101 \ --source-address-prefixes '*' --source-port-ranges '*' --destination-address-prefixes '*' \ --destination-port-ranges '*' --access Allow --protocol Icmp --description "Allowing All Icmp Traffic" # 创建允许Udp流量的规则 az network nsg rule create -g ${RG} --nsg-name "${RG}-nsg" -n ${RG}-nsg-rule-udp --priority 102 \ --source-address-prefixes '*' --source-port-ranges '*' --destination-address-prefixes '*' \ --destination-port-ranges '*' --access Allow --protocol Udp --description "Allowing All Udp Traffic"
注意:每个规则的--priority值必须唯一,不能重复
解决方案2:用通配符允许所有协议
如果你的需求是允许所有类型的流量,无需逐个指定协议,直接使用--protocol *即可,示例代码:
RG="Test-RG" az network nsg create --name "${RG}-nsg" --location "eastus" -g $RG az network nsg rule create -g ${RG} --nsg-name "${RG}-nsg" -n ${RG}-nsg-rule-all --priority 100 \ --source-address-prefixes '*' --source-port-ranges '*' --destination-address-prefixes '*' \ --destination-port-ranges '*' --access Allow --protocol '*' --description "Allowing All Traffic"
内容的提问来源于stack exchange,提问作者reddy malathi
相关产品推荐
相关产品推荐

