Add firewall script for managing inbound rules; support for domain profiles and interface aliases
This commit is contained in:
+13
-4
@@ -2,9 +2,17 @@
|
||||
param(
|
||||
[ValidateSet('Preview','Apply','Remove')][string]$Action = 'Preview',
|
||||
[string]$ProgramPath = (Join-Path $env:LOCALAPPDATA 'Programs\MusicBridge\MusicBridge.Agent.exe'),
|
||||
[ValidateRange(1,65535)][int]$Port = 8765
|
||||
[ValidateRange(1,65535)][int]$Port = 8765,
|
||||
[ValidateSet('Private','Domain')][string]$Profile = 'Private',
|
||||
[string]$InterfaceAlias
|
||||
)
|
||||
$ErrorActionPreference = 'Stop'
|
||||
if ($Profile -eq 'Domain' -and [string]::IsNullOrWhiteSpace($InterfaceAlias)) {
|
||||
throw 'Domain access requires an explicit home network InterfaceAlias.'
|
||||
}
|
||||
if ($InterfaceAlias -and ([string]::IsNullOrWhiteSpace($InterfaceAlias) -or $InterfaceAlias -eq 'Any' -or [Management.Automation.WildcardPattern]::ContainsWildcardCharacters($InterfaceAlias))) {
|
||||
throw 'Select one exact network interface, without wildcards.'
|
||||
}
|
||||
if (![IO.Path]::IsPathRooted($ProgramPath)) { throw 'ProgramPath must be absolute.' }
|
||||
$exe = [IO.Path]::GetFullPath($ProgramPath)
|
||||
if ([IO.Path]::GetFileName($exe) -ne 'MusicBridge.Agent.exe') { throw 'Select MusicBridge.Agent.exe.' }
|
||||
@@ -13,12 +21,13 @@ $sha = [Security.Cryptography.SHA256]::Create()
|
||||
try { $id = ([BitConverter]::ToString($sha.ComputeHash([Text.Encoding]::UTF8.GetBytes($exe.ToUpperInvariant())))).Replace('-','').Substring(0,16) }
|
||||
finally { $sha.Dispose() }
|
||||
$definitions = @(
|
||||
@{Name="MusicBridge-$id-HTTPS"; DisplayName='MusicBridge HTTPS (private LAN)'; Protocol='TCP'; LocalPort=$Port},
|
||||
@{Name="MusicBridge-$id-mDNS"; DisplayName='MusicBridge mDNS (private LAN)'; Protocol='UDP'; LocalPort=5353}
|
||||
@{Name="MusicBridge-$id-HTTPS"; DisplayName='MusicBridge HTTPS (local subnet)'; Protocol='TCP'; LocalPort=$Port},
|
||||
@{Name="MusicBridge-$id-mDNS"; DisplayName='MusicBridge mDNS (local subnet)'; Protocol='UDP'; LocalPort=5353}
|
||||
)
|
||||
foreach ($definition in $definitions) {
|
||||
$definition.Program = $exe
|
||||
$definition.Profile = 'Private'
|
||||
$definition.Profile = $Profile
|
||||
$definition.InterfaceAlias = if ($InterfaceAlias) { $InterfaceAlias } else { 'Any' }
|
||||
$definition.Direction = 'Inbound'
|
||||
$definition.Action = 'Allow'
|
||||
$definition.RemoteAddress = 'LocalSubnet'
|
||||
|
||||
Reference in New Issue
Block a user