使用API​​更新现有防火墙规则

use*_*483 9 c# api windows-firewall

我能够以编程方式将单个规则添加到Windows防火墙(Server 2008 R2),但是我试图避免每个IP地址有多个规则,并且只想更新现有规则RemoteAddresses.下面是我用来添加规则的代码,我正在尽力研究如何更新现有规则远程地址,但没有运气.

任何帮助表示赞赏!

string ip = "x.x.x.x";

INetFwRule2 firewallRule = (INetFwRule2)Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FWRule"));

firewallRule.Name = "Block Bad IP Addresses";
firewallRule.Description = "Block Nasty Incoming Connections from IP Address.";
firewallRule.Action = NET_FW_ACTION_.NET_FW_ACTION_BLOCK;
firewallRule.Direction = NET_FW_RULE_DIRECTION_.NET_FW_RULE_DIR_IN;
firewallRule.Enabled = true;
firewallRule.InterfaceTypes = "All";
firewallRule.RemoteAddresses = ip;

INetFwPolicy2 firewallPolicy = (INetFwPolicy2)Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FwPolicy2"));
firewallPolicy.Rules.Add(firewallRule);
Run Code Online (Sandbox Code Playgroud)

小智 10

以下代码适用于我:

INetFwPolicy2 firewallPolicy = (INetFwPolicy2) Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FwPolicy2"));

var rule = firewallPolicy.Rules.Item("Block Bad IP Addresses"); // Name of your rule here
rule.Name = "Block Block Block"; // Update the rule here. Nothing else needed to persist the changes
Run Code Online (Sandbox Code Playgroud)

  • 测试此代码的人员提示:更改按照描述保留,但可能不会出现在具有高级安全性的_Windows防火墙应用程序中,直到刷新显示后. (2认同)

Sla*_*ade 5

除了amdmax的答案(抱歉我无法添加注释)我发现没有简单的方法调用来检查规则是否存在所以我想出了这个以确保创建规则是否存在:

  INetFwPolicy2 firewallPolicy = (INetFwPolicy2)Activator.CreateInstance(
      Type.GetTypeFromProgID("HNetCfg.FwPolicy2"));

  INetFwRule firewallRule = firewallPolicy.Rules.OfType<INetFwRule>().Where(x => x.Name == RULE_NAME).FirstOrDefault();

  if (firewallRule == null)
  {
    firewallRule = (INetFwRule)Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FWRule"));
    firewallRule.Name = RULE_NAME;
    firewallPolicy.Rules.Add(firewallRule);
  }
Run Code Online (Sandbox Code Playgroud)


liv*_*ve2 5

我发现这个包可以通过 nuget WindowsFirewallHelper获得

PM> install-package WindowsFirewallHelper
Run Code Online (Sandbox Code Playgroud)

例子

PM> install-package WindowsFirewallHelper
Run Code Online (Sandbox Code Playgroud)