【问题标题】:Not able to add my client IP in server firewall rule无法在服务器防火墙规则中添加我的客户端 IP
【发布时间】:2020-03-21 14:12:12
【问题描述】:
我有两个订阅计划 QA-##### 和 Prod-########。第一个用于 QA 环境,第二个用于生产环境。在服务器防火墙列表中添加我的客户端 IP 后,我可以在 QA-###### 订阅上连接 Azure 数据库。
但我无法在 Prod-######## 订阅上连接 Azure SQL 数据库。当我要在服务器防火墙规则中添加我的客户端 IP 时,它显示成功消息但未在此处列出。
我还在 azure 帮助和支持部分提交了支持票,但没有回复。
【问题讨论】:
标签:
azure
azure-sql-database
firewall
【解决方案1】:
Azure 门户有时会出现影响一小部分 Azure 客户的问题。我的建议是在等待 Azure 支持解决问题时使用 PowerShell 添加所需的防火墙规则。
# Connect-AzAccount
# The SubscriptionId in which to create these objects
$SubscriptionId = ''
# Set the resource group name and location for your server
$resourceGroupName = "myResourceGroup-$(Get-Random)"
$location = "westus2"
# Set an admin login and password for your server
$adminSqlLogin = "SqlAdmin"
$password = "ChangeYourAdminPassword1"
# Set server name - the logical server name has to be unique in the system
$serverName = "server-$(Get-Random)"
$startIp = "0.0.0.0"
$endIp = "0.0.0.0"
# Set subscription
Set-AzContext -SubscriptionId $subscriptionId
# Create a resource group
$resourceGroup = New-AzResourceGroup -Name $resourceGroupName -Location $location
# Create a server with a system wide unique server name
$server = New-AzSqlServer -ResourceGroupName $resourceGroupName `
-ServerName $serverName `
-Location $location `
-SqlAdministratorCredentials $(New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList $adminSqlLogin, $(ConvertTo-SecureString -String $password -AsPlainText -Force))
# Create a server firewall rule that allows access from the specified IP range
$serverFirewallRule = New-AzSqlServerFirewallRule -ResourceGroupName $resourceGroupName `
-ServerName $serverName `
-FirewallRuleName "AllowedIPs" -StartIpAddress $startIp -EndIpAddress $endIp