Add firewall script for managing inbound rules; support for domain profiles and interface aliases
This commit is contained in:
@@ -13,4 +13,16 @@ if (($rules | Where-Object Protocol -eq UDP).LocalPort -ne 5353) { throw 'mDNS p
|
||||
$again = @(& $script -Action Preview -ProgramPath $exe -Port 8765)
|
||||
if (($rules.Name -join ',') -ne ($again.Name -join ',')) { throw 'Changing port would leave old rule names behind.' }
|
||||
& $script -Action Apply -ProgramPath $exe -WhatIf
|
||||
$domain = @(& $script -Action Preview -ProgramPath $exe -Profile Domain -InterfaceAlias Ethernet)
|
||||
foreach ($rule in $domain) {
|
||||
if ($rule.Profile -ne 'Domain' -or $rule.InterfaceAlias -ne 'Ethernet' -or $rule.RemoteAddress -ne 'LocalSubnet') { throw 'Domain scope mismatch.' }
|
||||
}
|
||||
if (($domain.Name -join ',') -ne ($rules.Name -join ',')) { throw 'Changing profile would leave old rules behind.' }
|
||||
foreach ($badAlias in @('', 'Any', 'Ether*', 'Ether?et')) {
|
||||
$rejected = $false
|
||||
try { & $script -Action Preview -ProgramPath $exe -Profile Domain -InterfaceAlias $badAlias | Out-Null }
|
||||
catch { $rejected = $true }
|
||||
if (!$rejected) { throw 'Domain scope accepted an unrestricted interface.' }
|
||||
}
|
||||
& $script -Action Apply -ProgramPath $exe -Profile Domain -InterfaceAlias Ethernet -WhatIf
|
||||
Write-Host 'PASS: private profile, local subnet, executable binding, ports, stable names and dry-run. No firewall changes.'
|
||||
|
||||
Reference in New Issue
Block a user