You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure中自动化创建NSG规则遇Get-AzNetworkSecurityGroup类型错误

Azure NSG规则自动化脚本问题修复

问题概述

编写PowerShell脚本为生产环境Azure网络安全组(NSG)自动化创建规则时,Get-AzNetworkSecurityGroup的返回值无法正常传入Add-AzNetworkSecurityRuleConfig,运行时要么无报错但规则未创建,要么出现以下错误:

Add-AzNetworkSecurityRuleConfig : Cannot bind argument to parameter 'NetworkSecurityGroup' because it is null.
或
Add-AzNetworkSecurityRuleConfig : Cannot bind parameter 'NetworkSecurityGroup'. Cannot convert the value of type "System.String" to type "Microsoft.Azure.Commands.Network.Models.PSNetworkSecurityGroup".

原脚本:

Import-Module Az.network
Connect-AzAccount
$tcpports = @(22,53,80,135,137,161,427,443,515,548,5060,5480,5985,5986,5989,9100,9443)
$udpports = @(53,161,427,515,548)
$solservers = #Server IP here
$file = Import-Csv C:\Users\temp\Downloads\AzureNSGs.csv

foreach ($NSG in $file){
$RGname=$NSG.'RESOURCE GROUP'
$nsgname=$NSG.NAME
$NSGObj = Get-AzNetworkSecurityGroup | Where-Object -Property Name -Like $RGname | Select-Object -Property Name
$name = "AllowSolarWinds"
    if($NSGObj){
    $name = $name + 1 
    $NSGObj | Add-AzNetworkSecurityRuleConfig -Name $name -NetworkSecurityGroup $NSGObj -Protocol Icmp -SourceAddressPrefix $solservers -DestinationPortRange "*" -Priority 555 
    $NSGObj | Set-AzNetworkSecurityGroup 
    }
}

错误原因

  1. NSG筛选逻辑错误:用NSG名称匹配资源组名称,完全不符合资源定位逻辑,导致无法正确获取目标NSG
  2. 对象截断:使用Select-Object -Property Name仅保留了名称字符串,丢失了完整的PSNetworkSecurityGroup对象,后续命令无法识别
  3. 规则名称处理不当:直接拼接字符串$name + 1会生成AllowSolarWinds1,但未检查NSG中是否已存在该名称,且逻辑简陋
  4. 冗余参数冲突:通过管道传递NSG对象时,重复指定-NetworkSecurityGroup参数,导致对象绑定混乱

修复后的脚本

Import-Module Az.Network
Connect-AzAccount

# 定义端口和源IP
$tcpports = @(22,53,80,135,137,161,427,443,515,548,5060,5480,5985,5986,5989,9100,9443)
$udpports = @(53,161,427,515,548)
$solservers = "192.168.1.10/32" # 替换为实际SolarWinds服务器IP/范围
$file = Import-Csv C:\Users\temp\Downloads\AzureNSGs.csv

foreach ($NSG in $file) {
    $RGname = $NSG.'RESOURCE GROUP'
    $nsgname = $NSG.NAME

    # 精准获取完整的NSG对象
    $NSGObj = Get-AzNetworkSecurityGroup -ResourceGroupName $RGname -Name $nsgname -ErrorAction SilentlyContinue

    if ($NSGObj) {
        $baseRuleName = "AllowSolarWinds"
        $ruleName = $baseRuleName
        $counter = 1

        # 检查规则名称是否已存在,避免重复
        while ($NSGObj.SecurityRules.Name -contains $ruleName) {
            $ruleName = "$baseRuleName$counter"
            $counter++
        }

        # 添加NSG规则(通过管道传递对象,无需重复指定NetworkSecurityGroup参数)
        $NSGObj = $NSGObj | Add-AzNetworkSecurityRuleConfig -Name $ruleName `
            -Protocol Icmp `
            -SourceAddressPrefix $solservers `
            -DestinationAddressPrefix "*" `
            -DestinationPortRange "*" `
            -Priority 555 `
            -Access Allow `
            -Direction Inbound

        # 提交更改到Azure
        $NSGObj | Set-AzNetworkSecurityGroup
        Write-Host "已为NSG $nsgname 添加规则 $ruleName"
    }
    else {
        Write-Warning "未找到资源组 $RGname 中的NSG $nsgname"
    }
}

关键修复点

  • 精准定位NSG:使用Get-AzNetworkSecurityGroup的-ResourceGroupName和-Name参数直接获取目标对象,避免全局遍历和筛选错误
  • 保留完整对象:移除Select-Object -Property Name,确保传递的是完整的PSNetworkSecurityGroup实例
  • 规则名称去重:循环检查现有规则名称,生成唯一的规则名,避免冲突
  • 简化参数传递:通过管道传递NSG对象,移除冗余的-NetworkSecurityGroup参数,避免绑定冲突
  • 显式参数声明:补充-Access和-Direction参数,提升脚本可读性和兼容性
  • 错误处理:添加-ErrorAction SilentlyContinue和警告提示,便于排查问题

内容的提问来源于stack exchange,提问作者sam.solo.works

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 04:05:53