You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NSG规则自动化脚本异常:已配置源IP仍误删入站规则求助

修复NSG规则自动化管理脚本的错误

原脚本的核心问题

  1. 循环变量引用错误:foreach循环里误用了$_,当前循环变量是$nsgRule,$_在此上下文为空,直接导致条件判断完全失效。
  2. 无效条件逻辑:DestinationPortRange -eq -split ('')是无意义代码,-split ''不会生成有效取值,且判断逻辑和你要检测的「源IP地址是否存在」完全无关。
  3. 判断对象错误:你需要检测的是源IP(SourceAddressPrefix),但原脚本错误地对目标地址/端口做判断,最终导致符合预期的规则被误删。

修正后的脚本(按需求定制)

如果你需要删除未指定特定源IP的入站规则(即源IP为默认*的规则,保留已添加特定IP的规则),使用以下脚本:

$nsg = Get-AzNetworkSecurityGroup -ResourceGroupName Testingday4
$nsgRules = Get-AzNetworkSecurityRuleConfig -NetworkSecurityGroup $nsg

foreach($nsgRule in $nsgRules)
{
    # 仅处理入站规则,且源IP为默认的"*"(未指定特定源IP)时执行删除
    if($nsgRule.Direction -eq "inbound" -and $nsgRule.SourceAddressPrefix -eq "*"){
        Write-Host "删除规则: $($nsgRule.Name)"
        Remove-AzNetworkSecurityRuleConfig -Name $nsgRule.Name -NetworkSecurityGroup $nsg
    }
}

$nsg | Set-AzNetworkSecurityGroup

如果你的需求是保留指定源IP的规则,删除其他入站规则(比如保留192.168.1.0/24的规则),可调整条件:

$targetSourceIP = "192.168.1.0/24" # 替换为你需要保留的源IP
$nsg = Get-AzNetworkSecurityGroup -ResourceGroupName Testingday4
$nsgRules = Get-AzNetworkSecurityRuleConfig -NetworkSecurityGroup $nsg

foreach($nsgRule in $nsgRules)
{
    if($nsgRule.Direction -eq "inbound" -and $nsgRule.SourceAddressPrefix -ne $targetSourceIP){
        Write-Host "删除规则: $($nsgRule.Name)"
        Remove-AzNetworkSecurityRuleConfig -Name $nsgRule.Name -NetworkSecurityGroup $nsg
    }
}

$nsg | Set-AzNetworkSecurityGroup

关键修正说明

  • 替换$_为$nsgRule,确保正确引用当前遍历的规则对象
  • 将判断逻辑聚焦到SourceAddressPrefix(源IP地址前缀),匹配你的核心需求
  • 添加Write-Host输出删除的规则名称,方便验证执行结果
  • 移除原脚本中无效的代码片段,避免逻辑混乱

内容的提问来源于stack exchange,提问作者bunny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 22:30:53