从文本文件读取并批量添加多条防火墙规则的脚本实现需求
Solution to Deploy Multiple Firewall Rules Across Servers
Got it, let's tweak your script to deploy all four required firewall rules to each server in your list, while keeping the "only create if missing" logic intact. Here's a streamlined, maintainable approach:
Modified Script
# Read list of target computers $Computers = Get-Content -Path "C:\temp\kofaxcomputers.txt" # Define all 4 firewall rules as an array of objects (easy to update later) $firewallRules = @( @{ DisplayName = "k1 (TCP- In)" Direction = "Inbound" LocalPort = 2424 # Replace with actual port for k1 if different Protocol = "TCP" }, @{ DisplayName = "k2 (TCP- Out)" Direction = "Outbound" LocalPort = 2425 # Replace with actual port for k2 if different Protocol = "TCP" }, @{ DisplayName = "k3 (TCP- In)" Direction = "Inbound" LocalPort = 2426 # Replace with actual port for k3 if different Protocol = "TCP" }, @{ DisplayName = "k4 (TCP- Out)" Direction = "Outbound" LocalPort = 2427 # Replace with actual port for k4 if different Protocol = "TCP" } ) Write-Host "Initiating firewall rule checks and deployments across $($Computers.Count) servers..." -ForegroundColor Cyan # Run commands on each remote server Invoke-Command -ComputerName $Computers { param($Rules) foreach ($rule in $Rules) { # Check if a rule with the same DisplayName AND Direction already exists $existingRule = Get-NetFirewallRule | Where-Object { $_.DisplayName -eq $rule.DisplayName -and $_.Direction -eq $rule.Direction } if ($existingRule) { Write-Host "[$env:COMPUTERNAME] Firewall rule '$($rule.DisplayName)' already exists - skipping creation" -ForegroundColor Red } else { Write-Host "[$env:COMPUTERNAME] Creating firewall rule '$($rule.DisplayName)'..." -ForegroundColor Yellow New-NetFirewallRule -DisplayName $rule.DisplayName ` -Direction $rule.Direction ` -RemoteAddress Any ` -Action Allow ` -Protocol $rule.Protocol ` -LocalPort $rule.LocalPort Write-Host "[$env:COMPUTERNAME] Rule '$($rule.DisplayName)' created successfully" -ForegroundColor Green } } } -ArgumentList $firewallRules Write-Host "Firewall rule deployment process completed!" -ForegroundColor Cyan
Key Improvements & Explanations
Centralized Rule Definition
- We've stored all four rules in an array of hashtables. This makes it easy to add/remove rules later without rewriting loop logic. Just update the
$firewallRulesarray with new rule details.
- We've stored all four rules in an array of hashtables. This makes it easy to add/remove rules later without rewriting loop logic. Just update the
Precise Existence Check
- The original script checked for any rule with the same name (regardless of direction). Now we match both
DisplayNameandDirectionexactly, which aligns with your requirement to skip creation only if a rule with the same name AND direction exists.
- The original script checked for any rule with the same name (regardless of direction). Now we match both
Server Context in Output
- Added
[$env:COMPUTERNAME]to all output messages, so you can easily track which server each log entry applies to when running against multiple machines.
- Added
Reusable Logic
- Using a
foreachloop inside the remote session means we don't have to duplicate the check/create code four times—we just iterate over our rule list once.
- Using a
Notes
- Make sure to replace the placeholder
LocalPortvalues in the$firewallRulesarray with the actual ports required for each rule. - Ensure that PSRemoting is enabled on all target servers (you can run
Enable-PSRemoting -Forceon each server if needed, or via GPO for enterprise environments).
内容的提问来源于stack exchange,提问作者wazzie
相关产品推荐
相关产品推荐

