Add firewall script for managing inbound rules; support for domain profiles and interface aliases

This commit is contained in:
2026-09-10 08:56:22 +03:00
parent 369c0347a7
commit e9931cb941
5 changed files with 108 additions and 6 deletions
+12
View File
@@ -13,4 +13,16 @@ if (($rules | Where-Object Protocol -eq UDP).LocalPort -ne 5353) { throw 'mDNS p
$again = @(& $script -Action Preview -ProgramPath $exe -Port 8765)
if (($rules.Name -join ',') -ne ($again.Name -join ',')) { throw 'Changing port would leave old rule names behind.' }
& $script -Action Apply -ProgramPath $exe -WhatIf
$domain = @(& $script -Action Preview -ProgramPath $exe -Profile Domain -InterfaceAlias Ethernet)
foreach ($rule in $domain) {
if ($rule.Profile -ne 'Domain' -or $rule.InterfaceAlias -ne 'Ethernet' -or $rule.RemoteAddress -ne 'LocalSubnet') { throw 'Domain scope mismatch.' }
}
if (($domain.Name -join ',') -ne ($rules.Name -join ',')) { throw 'Changing profile would leave old rules behind.' }
foreach ($badAlias in @('', 'Any', 'Ether*', 'Ether?et')) {
$rejected = $false
try { & $script -Action Preview -ProgramPath $exe -Profile Domain -InterfaceAlias $badAlias | Out-Null }
catch { $rejected = $true }
if (!$rejected) { throw 'Domain scope accepted an unrestricted interface.' }
}
& $script -Action Apply -ProgramPath $exe -Profile Domain -InterfaceAlias Ethernet -WhatIf
Write-Host 'PASS: private profile, local subnet, executable binding, ports, stable names and dry-run. No firewall changes.'