You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否将Azure虚拟机端口开放配置整合到创建API请求中?

可以将端口开放配置整合到创建VM的API请求中

当然可以!az vm open-port --port 3389这条命令的本质是给虚拟机关联的**网络安全组(NSG)**添加一条允许3389端口(RDP)入站访问的规则。你完全可以把这条规则的配置直接整合到创建VM的API请求里,无需单独执行命令行工具。

具体实现分两种常见场景:

场景1:创建VM时同时创建新网卡和包含3389规则的NSG

如果你的VM不需要依赖现有网卡,可以在API请求中直接定义新网卡,并为其关联一个包含3389入站规则的NSG。修改后的请求体示例如下:

{
  "location": "westus",
  "properties": {
    "hardwareProfile": {
      "vmSize": "Standard_D1_v2"
    },
    "storageProfile": {
      "imageReference": {
        "sku": "2016-Datacenter",
        "publisher": "MicrosoftWindowsServer",
        "version": "latest",
        "offer": "WindowsServer"
      },
      "osDisk": {
        "caching": "ReadWrite",
        "managedDisk": {
          "storageAccountType": "Standard_LRS"
        },
        "name": "myVMosdisk",
        "createOption": "FromImage"
      }
    },
    "osProfile": {
      "adminUsername": "{your-username}",
      "computerName": "myVM",
      "adminPassword": "{your-password}"
    },
    "networkProfile": {
      "networkInterfaces": [
        {
          "properties": {
            "primary": true,
            "ipConfigurations": [
              {
                "name": "ipconfig1",
                "properties": {
                  "subnet": {
                    "id": "/subscriptions/{subscription-id}/resourceGroups/myResourceGroup/providers/Microsoft.Network/virtualNetworks/{vnet-name}/subnets/{subnet-name}"
                  },
                  "privateIPAllocationMethod": "Dynamic"
                }
              }
            ],
            "networkSecurityGroup": {
              "properties": {
                "securityRules": [
                  {
                    "name": "AllowRDP",
                    "properties": {
                      "protocol": "Tcp",
                      "sourcePortRange": "*",
                      "destinationPortRange": "3389",
                      "sourceAddressPrefix": "*",
                      "destinationAddressPrefix": "*",
                      "access": "Allow",
                      "priority": 1000,
                      "direction": "Inbound"
                    }
                  }
                ]
              },
              "location": "westus"
            }
          }
        }
      ]
    }
  }
}

场景2:使用现有网卡(需提前配置NSG规则)

如果你坚持使用原请求中引用的现有网卡{existing-nic-name},则需要确保该网卡关联的NSG已经包含3389端口的入站规则。若NSG还没有这条规则,你需要在创建VM前通过NSG专属API添加规则,但这种方式无法将操作完全整合到一个VM创建请求里,因此更推荐场景1的方案。

关键注意点:

  • NSG规则的priority(优先级)数值越小,规则优先级越高,要确保它不会被其他拒绝类规则覆盖。
  • sourceAddressPrefix设为*表示允许所有外部IP访问3389端口,若需限制访问来源,可替换为特定IP段(如192.168.1.0/24)。
  • 场景1的示例中,我们直接在网卡配置里嵌套了NSG定义,Azure会自动创建该NSG并关联到新网卡,无需额外操作。

内容的提问来源于stack exchange,提问作者Aderbal Farias

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:21:25