• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

reset anti-lockout rule

Scheduled Pinned Locked Moved General pfSense Questions
8 Posts 3 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    wifi75
    last edited by Jan 18, 2022, 2:51 PM

    hello I have created an aggregation 4 4 LACP network interfaces. the automatically created anti-lockout rule disappeared in the firewall, how can I restore it?

    G 1 Reply Last reply Jan 18, 2022, 3:13 PM Reply Quote 0
    • G
      Gertjan @wifi75
      last edited by Jan 18, 2022, 3:13 PM

      @wifi75

      Goto System > Advanced >Admin Access
      and remove the check from :

      ee2180a5-ed01-4475-90b2-949289337bb8-image.png

      Result :

      dc93736b-8c1e-4a6d-932c-a9079265a351-image.png

      I works for a LAN type interface.
      Dono if "aggregation 4 4 LACP" is considered as a "normal" interface.

      The good new : the rule is nothing special - and not essential.
      It's a pass rule for ports 80 and 443, TCP, source : the connected network, for a LAN this is "LAN Address". This rule must be at the top of the rule list.

      It's just a anti shoot in the foot rule, and placed on the LAN interface where only trusted (by the admin) devices are connected.
      All other devices belong on other 'LAN' type interface, and these networks do (should) not have access to the pfSense GUI (the should have a rule that blocks the GUI traffic).

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      W 1 Reply Last reply Jan 18, 2022, 3:25 PM Reply Quote 0
      • S
        stephenw10 Netgate Administrator
        last edited by Jan 18, 2022, 3:24 PM

        It probably just moved to the new interface when you assigned it. That's expected if you previously only had WAN assigned.

        1 Reply Last reply Reply Quote 0
        • W
          wifi75 @Gertjan
          last edited by Jan 18, 2022, 3:25 PM

          @gertjan to me it is already like this without the flag

          G 1 Reply Last reply Jan 18, 2022, 4:42 PM Reply Quote 0
          • G
            Gertjan @wifi75
            last edited by Jan 18, 2022, 4:42 PM

            @wifi75
            the documentation ** is here : /etc/inc/filter.inc :
            It says :
            /* if antilockout is enabled, LAN exists and has
            * an IP and subnet mask assigned
            */
            for systems with more then 1 interface, and one interface is known as the 'lan'.
            Or, systems with 1 interface, and that interface is known as the 'wan'.

            I guess your "LACP" isn't isn't qualified as the 'lan'.

            Don't bother : create the rule yourself on the interface you like.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by stephenw10 Jan 18, 2022, 4:55 PM Jan 18, 2022, 4:53 PM

              Looks like you may be running a very old version: https://forum.netgate.com/post/1020459
              Unless that's not your screenshot.

              Not that it should make any difference to this.

              W 1 Reply Last reply Jan 18, 2022, 5:48 PM Reply Quote 0
              • W
                wifi75 @stephenw10
                last edited by Jan 18, 2022, 5:48 PM

                @stephenw10 linke this it is ok?
                f9baaa17-97f0-47f5-9337-b48a3525a935-image.png

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Jan 18, 2022, 6:02 PM

                  That looks fine for general access.

                  You don't really need those top two rules, the pass-all rule covers that traffic.

                  The anti-lockout rule will be on your VLAN10 interface.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  4 out of 8
                  • First post
                    4/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received