Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot gain remote access to WebUI

    Scheduled Pinned Locked Moved Firewalling
    26 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      orangehand @orangehand
      last edited by

      @orangehand sorry - yes, it's a public routable IP, and ovpn works fine back to that address.

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @orangehand
        last edited by

        @orangehand said in Cannot gain remote access to WebUI:

        I'd tried any. No dice!

        Oh yes, that valid usefull info !!

        Now I know that nothing reaches your pfSense WAN interface, port 8082, TCP.
        Otherwise, the rule would be a match.
        That is, I presume :

        1. you connect like this : https://some-url-to-you-wan-IP-here.tld:8082 (or : https://a.b.c.d:8082)
          and
        2. You do not connect from within your LAN, but you are using your phone with the Wifi shut down = you are really connecting from the out side.

        Also : using IPv4, right, not IPv6.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @Gertjan
          last edited by Gertjan

          You can start a packet capture on your WAN interface.
          Select TCP - and port 8082.

          If something comes in, it will get captured in the resulting log.

          edit : like this :

          1ed8bd3b-ca4b-4690-987a-2b9192d5ea33-image.png

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          O 1 Reply Last reply Reply Quote 0
          • O
            orangehand @Gertjan
            last edited by

            @gertjan 1: yes and 2: I am remote on my own FTTP LAN so it is a true test with no risk of cgnat etc

            Will try the packet capture, thanks

            O 1 Reply Last reply Reply Quote 0
            • O
              orangehand @orangehand
              last edited by

              @orangehand output is:

              10:05:57.099569 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:05:58.197408 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:05:59.281622 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:06:00.328195 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:06:01.351961 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:06:02.383762 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:06:04.445801 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0
              10:06:08.830995 IP 62.3.69.70.23841 > 51.148.184.62.8082: tcp 0

              I have to confess I don't know if this is good or bad!

              O 1 Reply Last reply Reply Quote 0
              • O
                orangehand @orangehand
                last edited by

                @orangehand the IP's are correct

                GertjanG O 2 Replies Last reply Reply Quote 0
                • GertjanG
                  Gertjan @orangehand
                  last edited by

                  @orangehand said in Cannot gain remote access to WebUI:

                  the IP's are correct

                  I tested
                  https://51.148.xx.62 port 8082
                  ... nothing replied like nothing is listening on that port.

                  sockstat -l | grep '8082
                  

                  confirms that the GUI webserver is listening on 8082 ?

                  Or go back to the default 443 for a moment.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  O 2 Replies Last reply Reply Quote 0
                  • O
                    orangehand @orangehand
                    last edited by

                    @orangehand This box was a new SG1100 which I installed yesterday. Out of the box it was not working at all well. I had to reflash it using the recovery image sent by Netgate. This image retains the original settings, or some of them. I am wondering if the reflash has cured all the problems. Anyone know how I would totally reset it to defaults? Another odd issue I am having is that MY OpenVPN connection to that box was working earlier this morning when I set it up and now, with no changes to the 1100, it is not. The customer's own ovpn connection from INSIDE his LAN is working fine.

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • O
                      orangehand @Gertjan
                      last edited by

                      @gertjan Thanks. Will revert to 443 and see what I get.

                      1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @orangehand
                        last edited by

                        @orangehand said in Cannot gain remote access to WebUI:

                        Anyone know how I would totally reset it to defaults?

                        A refaslh will do that.

                        Or use the console or SSH option

                        4) Reset to factory defaults
                        

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        O 1 Reply Last reply Reply Quote 0
                        • O
                          orangehand @Gertjan
                          last edited by

                          @gertjan what is the supported way of doing a total reflash? The wiki only refers to using the recovery image, which isn't a true factory reset, as it retains some previous settings.

                          GertjanG 1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @orangehand
                            last edited by

                            @orangehand

                            When I used a USB device, I always repartitioned the device's drive.
                            If there was a question of "found a config from a previously installed pfSense' I would chose "don't take it".
                            Or, as said above : use the "4" option.
                            or GUI Diagnostics > Factory Defaults

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            1 Reply Last reply Reply Quote 0
                            • O
                              orangehand @Gertjan
                              last edited by

                              @gertjan Really odd. Setting the box back to standard admin ports was the answer. Odd, as I have a dozen other pfsense boxes on custom ports with me having remote management, and all work fine. Any guesses?

                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @orangehand
                                last edited by

                                @orangehand

                                Did you do de sockstat test ?

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                O 1 Reply Last reply Reply Quote 0
                                • O
                                  orangehand @Gertjan
                                  last edited by

                                  @gertjan tbh I didn't understand how to do it! Can you clarify please?

                                  GertjanG 1 Reply Last reply Reply Quote 0
                                  • GertjanG
                                    Gertjan @orangehand
                                    last edited by

                                    @orangehand
                                    You have to use the most important interface : the console access.
                                    Or a SSH access. But keep in mind that SSH isn't available when you install pfSense on a device, as interfaces aren't assigned (known) yet.
                                    See the pfSense documentation. These two accesses are not some optional thing. Without them, you're "doomed".

                                    The console access or SSH permits you to enter commands.
                                    Like sockstat -l | grep '8082

                                    No "help me" PM's please. Use the forum, the community will thank you.
                                    Edit : and where are the logs ??

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.