You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何向Azure NSG规则批量添加数千IP并避免命令长度超限问题

解决方案

核心问题说明

你遇到的两个报错根因分别是:

  • 调用Azure CLI时,大量IP被展开为命令行参数,超过了操作系统的命令行长度上限(Windows默认8191字符)
  • 之前使用PowerShell Az模块时,将SourceAddressPrefix赋值为逗号拼接的长字符串,触发了字符串长度限制,实际Az模块支持直接传入IP数组对象,完全可以规避这个问题
    另外你提到的覆盖原有IP的问题,只需要先读取现有规则的IP列表,和新IP合并去重后再提交即可实现增量追加。

完整PowerShell实现方案

步骤1:基础配置与IP合并

# 自定义配置项
$resourceGroupName = "替换为你的资源组名"
$nsgName = "替换为你的NSG名称"
$baseRuleName = "Blocked_IP"
$newIpFilepath = ".\file.txt"
$maxIpsPerRule = 4000 # Azure NSG单规则IP上限

# 获取NSG对象
$nsg = Get-AzNetworkSecurityGroup -Name $nsgName -ResourceGroupName $resourceGroupName

# 读取现有规则的IP列表
$existingIps = @()
$relatedRules = $nsg.SecurityRules | Where-Object {$_.Name -like "$baseRuleName*"}
foreach ($rule in $relatedRules) {
    $existingIps += $rule.SourceAddressPrefix
}

# 读取新IP,去重过滤空行
$newIps = Get-Content $newIpFilepath | Where-Object {$_.Trim() -ne ""} | Select-Object -Unique

# 合并新旧IP并整体去重
$allIps = $existingIps + $newIps | Select-Object -Unique

步骤2:更新NSG规则(自动适配IP数量)

当合并后IP总数不超过4000时直接更新原有规则,超过时自动拆分多规则:

# 先删除原有同名规则组
$nsg.SecurityRules = $nsg.SecurityRules | Where-Object {$_.Name -notlike "$baseRuleName*"}

# 按4000个/组拆分IP
$ipGroups = for ($i = 0; $i -lt $allIps.Count; $i += $maxIpsPerRule) {
    $endIndex = [Math]::Min($i + $maxIpsPerRule - 1, $allIps.Count - 1)
    ,$allIps[$i..$endIndex]
}

# 批量添加规则,优先级依次顺延
$basePriority = 500
for ($j = 0; $j -lt $ipGroups.Count; $j++) {
    $currentRuleName = if ($j -eq 0) { $baseRuleName } else { "$baseRuleName`_$j" }
    Add-AzNetworkSecurityRuleConfig -NetworkSecurityGroup $nsg `
        -Name $currentRuleName `
        -Protocol Tcp `
        -Direction Inbound `
        -Priority ($basePriority + $j) `
        -SourceAddressPrefix $ipGroups[$j] `
        -SourcePortRange "*" `
        -DestinationAddressPrefix "*" `
        -DestinationPortRange "3389" `
        -Access Deny
}

# 提交所有更改到Azure
$nsg | Set-AzNetworkSecurityGroup

每日自动运行配置

把上述脚本保存为.ps1文件,上传到Azure自动化账户的PowerShell Runbook,配置每日定时触发即可实现自动更新,不需要本地常驻环境。

内容的提问来源于stack exchange,提问作者Shahar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 19:15:06