You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用PowerShell在FortiGate配置文件指定区块内查找替换set ip行

Solution: Targeted IP Replacement in FortiGate Config with PowerShell

Got it, let's fix that FortiGate config editing task. Matching the exact wan1 interface block inside config system interface can be tricky with multi-line regex (PowerShell's handling of it is finicky, especially with nested config blocks). Instead, let's use a context-tracking approach that's reliable and easy to adjust.

Step 1: Filter Out Unwanted Lines

First, we'll keep your existing filter to remove comments and UUID lines—those don't affect our config change:

$configPath = ".\Fortigate.conf"
$filteredContent = Get-Content $configPath | Where-Object { 
    $_ -notmatch '^#' -and $_ -notmatch 'set uuid ' 
}

Step 2: Track Context to Target the Right Block

We'll iterate through each line, keeping track of whether we're inside the config system interface block and then the edit "wan1" sub-block. This ensures we only replace the set ip line in the exact section you need:

$inSystemInterface = $false
$inWan1Edit = $false
$modifiedConfig = @()

# Define your new WAN IP and subnet here
$newWanIp = "203.0.113.5"
$newSubnet = "255.255.255.0"

foreach ($line in $filteredContent) {
    # Enter system interface config block
    if ($line -match '^config system interface') {
        $inSystemInterface = $true
        $modifiedConfig += $line
        continue
    }

    # Exit system interface config block
    if ($inSystemInterface -and $line -match '^end') {
        $inSystemInterface = $false
        $inWan1Edit = $false
        $modifiedConfig += $line
        continue
    }

    # Enter wan1 edit block
    if ($inSystemInterface -and $line -match '^edit "wan1"') {
        $inWan1Edit = $true
        $modifiedConfig += $line
        continue
    }

    # Exit wan1 edit block (each interface edit has its own end)
    if ($inWan1Edit -and $line -match '^end') {
        $inWan1Edit = $false
        $modifiedConfig += $line
        continue
    }

    # Replace the set ip line only if we're in the wan1 block
    if ($inWan1Edit -and $line -match '^set ip ') {
        $modifiedConfig += "set ip $newWanIp $newSubnet"
        continue
    }

    # Keep all other lines as-is
    $modifiedConfig += $line
}

# Save to a new file (always verify before overwriting the original!)
$modifiedConfig | Out-File ".\Modified_Fortigate.conf" -Encoding UTF8

Why This Works Better Than Regex

  • Avoids regex pitfalls: Multi-line regex in PowerShell requires enabling single-line mode ((?s)), but FortiGate configs can have nested blocks that break pattern matching. Context tracking is more robust.
  • Precise targeting: We only modify the set ip line inside the exact wan1 interface under config system interface—no chance of accidentally changing other set ip lines elsewhere in the config.
  • Easy to adjust: You can tweak the matching patterns (e.g., if your config uses indentation) or add more replacements (like set gateway) without rewriting complex regex.

Important Notes

  • Replace $newWanIp and $newSubnet with your actual WAN IP address and subnet mask.
  • Always save to a new file first, then compare it with the original to confirm the changes are correct before overwriting.
  • If your FortiGate config uses indentation (e.g., lines start with tabs/spaces), adjust the regex patterns to match (e.g., ^\s*edit "wan1" instead of ^edit "wan1").

内容的提问来源于stack exchange,提问作者DimiBoy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:54:26