您好,登錄后才能下訂單哦!
在C#中如何設(shè)置防火墻規(guī)則?很多新手對(duì)此不是很清楚,為了幫助大家解決這個(gè)難題,下面小編將為大家詳細(xì)講解,有這方面需求的人可以來(lái)學(xué)習(xí)下,希望你能有所收獲。
創(chuàng)建規(guī)則的方法:
/// <summary> /// 為WindowsDefender防火墻添加一條通信端口出站規(guī)則 /// </summary> /// <param name="type">規(guī)則類(lèi)型</param> /// <param name="ruleName">規(guī)則名稱</param> /// <param name="appPath">應(yīng)用程序完整路徑</param> /// <param name="localAddresses">本地地址</param> /// <param name="localPorts">本地端口</param> /// <param name="remoteAddresses">遠(yuǎn)端地址</param> /// <param name="remotePorts">遠(yuǎn)端端口</param> public static bool CreateOutRule(NET_FW_IP_PROTOCOL_ type, string ruleName, string appPath, string localAddresses = null, string localPorts = null, string remoteAddresses = null, string remotePorts = null) { //創(chuàng)建防火墻策略類(lèi)的實(shí)例 INetFwPolicy2 policy2 = (INetFwPolicy2)Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FwPolicy2")); //檢查是否有同名規(guī)則 foreach (INetFwRule item in policy2.Rules) { if (item.Name == ruleName) { return true; } } //創(chuàng)建防火墻規(guī)則類(lèi)的實(shí)例: 有關(guān)該接口的詳細(xì)介紹:https://docs.microsoft.com/zh-cn/windows/win32/api/netfw/nn-netfw-inetfwrule INetFwRule rule = (INetFwRule)Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FwRule")); //為規(guī)則添加名稱 rule.Name = ruleName; //為規(guī)則添加描述 rule.Description = "禁止程序訪問(wèn)非指定端口"; //選擇入站規(guī)則還是出站規(guī)則,IN為入站,OUT為出站 rule.Direction = NET_FW_RULE_DIRECTION_.NET_FW_RULE_DIR_OUT; //為規(guī)則添加協(xié)議類(lèi)型 rule.Protocol = (int)type; //為規(guī)則添加應(yīng)用程序(注意這里是應(yīng)用程序的絕對(duì)路徑名) rule.ApplicationName = appPath; //為規(guī)則添加本地IP地址 if (!string.IsNullOrEmpty(localAddresses)) { rule.LocalAddresses = localAddresses; } //為規(guī)則添加本地端口 if (!string.IsNullOrEmpty(localPorts)) { //需要移除空白字符(不能包含空白字符,下同) rule.LocalPorts = localPorts.Replace(" ", "");// "1-29999, 30003-33332, 33334-55554, 55556-60004, 60008-65535"; } //為規(guī)則添加遠(yuǎn)程IP地址 if (!string.IsNullOrEmpty(remoteAddresses)) { rule.RemoteAddresses = remoteAddresses; } //為規(guī)則添加遠(yuǎn)程端口 if (!string.IsNullOrEmpty(remotePorts)) { rule.RemotePorts = remotePorts.Replace(" ", ""); } //設(shè)置規(guī)則是阻止還是允許(ALLOW=允許,BLOCK=阻止) rule.Action = NET_FW_ACTION_.NET_FW_ACTION_BLOCK; //分組 名 rule.Grouping = "GroupsName"; rule.InterfaceTypes = "All"; //是否啟用規(guī)則 rule.Enabled = true; try { //添加規(guī)則到防火墻策略 policy2.Rules.Add(rule); } catch (Exception e) { string error = $"防火墻添加規(guī)則出錯(cuò):{ruleName} {e.Message}"; AppLog.Error(error); throw new Exception(error); } return true; }
創(chuàng)建TCP的出站規(guī)則
使用上述代碼,為創(chuàng)建一條TCP類(lèi)型的出站規(guī)則:
/// <summary> /// 為WindowsDefender防火墻添加一條U3D通信TCP端口出站規(guī)則 /// </summary> /// <param name="appPath">應(yīng)用程序完整路徑</param> /// <param name="localAddresses">本地地址</param> /// <param name="localPorts">本地端口</param> /// <param name="remoteAddresses">遠(yuǎn)端地址</param> /// <param name="remotePorts">遠(yuǎn)端端口</param> public static bool CreateTCPOutRule(string appPath, string localAddresses = null, string localPorts = null, string remoteAddresses = null, string remotePorts = null) { try { string ruleName = $"{System.IO.Path.GetFileNameWithoutExtension(appPath)}TCP"; CreateOutRule(NET_FW_IP_PROTOCOL_.NET_FW_IP_PROTOCOL_TCP, ruleName, appPath, localAddresses, localPorts, remoteAddresses, remotePorts); } catch (Exception e) { AppLog.Error(e.Message); throw new Exception(e.Message); } return true; }
創(chuàng)建UDP的出站規(guī)則
和TCP的出站規(guī)則類(lèi)似,只是傳入的類(lèi)型不一樣。使用前面的代碼,創(chuàng)建一條UDP的出站規(guī)則:
/// <summary> /// 為WindowsDefender防火墻添加一條通信UDP端口出站規(guī)則 /// </summary> /// <param name="appPath">應(yīng)用程序完整路徑</param> /// <param name="localAddresses">本地地址</param> /// <param name="localPorts">本地端口</param> /// <param name="remoteAddresses">遠(yuǎn)端地址</param> /// <param name="remotePorts">遠(yuǎn)端端口</param> public static bool CreateUDPOutRule(string appPath, string localAddresses = null, string localPorts = null, string remoteAddresses = null, string remotePorts = null) { try { string ruleName = $"{System.IO.Path.GetFileNameWithoutExtension(appPath)}UDP"; CreateOutRule(NET_FW_IP_PROTOCOL_.NET_FW_IP_PROTOCOL_UDP, ruleName, appPath, localAddresses, localPorts, remoteAddresses, remotePorts); } catch (Exception e) { AppLog.Error(e.Message); throw new Exception(e.Message); } return true; }
刪除出入站規(guī)則
注意出入站規(guī)則的名稱,前面我創(chuàng)建出站規(guī)則的時(shí)候,使用的“應(yīng)用程序名+網(wǎng)絡(luò)類(lèi)型”創(chuàng)建的,所以刪除時(shí),傳入的名稱也應(yīng)一樣,并且還可以判斷網(wǎng)絡(luò)類(lèi)型是否一致,一致才刪除。
/// <summary> /// 刪除WindowsDefender防火墻規(guī)則 /// <summary> /// <param name="appPath">應(yīng)用程序完整路徑</param> public static bool DeleteRule(string appPath) { //創(chuàng)建防火墻策略類(lèi)的實(shí)例 INetFwPolicy2 policy2 = (INetFwPolicy2)Activator.CreateInstance(Type.GetTypeFromProgID("HNetCfg.FwPolicy2")); string ruleName = System.IO.Path.GetFileNameWithoutExtension(appPath); try { //根據(jù)規(guī)則名稱移除規(guī)則 policy2.Rules.Remove(ruleName); } catch (Exception e) { string error = $"防火墻刪除規(guī)則出錯(cuò):{ruleName} {e.Message}"; AppLog.Error(error); throw new Exception(error); } return true; }
看完上述內(nèi)容是否對(duì)您有幫助呢?如果還想對(duì)相關(guān)知識(shí)有進(jìn)一步的了解或閱讀更多相關(guān)文章,請(qǐng)關(guān)注億速云行業(yè)資訊頻道,感謝您對(duì)億速云的支持。
免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點(diǎn)不代表本網(wǎng)站立場(chǎng),如果涉及侵權(quán)請(qǐng)聯(lián)系站長(zhǎng)郵箱:is@yisu.com進(jìn)行舉報(bào),并提供相關(guān)證據(jù),一經(jīng)查實(shí),將立刻刪除涉嫌侵權(quán)內(nèi)容。