Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    GUI Lockout?!

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @furom
      last edited by

      @furom said in GUI Lockout?!:

      Why please?

      When setting up access methods, first, access a console (SSH or the classic console) and

      tail -f /var/log/system.log
      

      Or look constantly here Status > System Logs > System > General

      Normally, on the LAN interface, there should be a rule like this :
      4733d22d-29ec-4563-bacb-89a179010c50-image.png

      Without this rule, and arrros during SSH access, the process "sshguard" (will also scan failed GUI access) will block you LAN IP.

      If you suspect that you're locked out : assign temporarily a static IP / mask Gateway /DNS to your device you use to access pfSense which is different as the previous (DHCP) IP, and don't make the same mistake twice.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      F 1 Reply Last reply Reply Quote 0
      • F
        furom @Gertjan
        last edited by

        @gertjan said in GUI Lockout?!:

        @furom said in GUI Lockout?!:

        Why please?

        When setting up access methods, first, access a console (SSH or the classic console) and

        tail -f /var/log/system.log
        

        Or look constantly here Status > System Logs > System > General

        Normally, on the LAN interface, there should be a rule like this :
        4733d22d-29ec-4563-bacb-89a179010c50-image.png

        Without this rule, and arrros during SSH access, the process "sshguard" (will also scan failed GUI access) will block you LAN IP.

        If you suspect that you're locked out : assign temporarily a static IP / mask Gateway /DNS to your device you use to access pfSense which is different as the previous (DHCP) IP, and don't make the same mistake twice.

        Absolutely. But the issue was more of that despite I had these ports wide open for what I need, I got blocked. I have, added such rule to my main net as well and topmost. I don't doubt I have done something dumb, but I could not find it. Rules evaluates top down, and according to that I should have had all these ports open already. Thanks for reminding me tho. I have it on LAN, but should really be made available on other ones too, or as a choice...

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @furom
          last edited by

          @furom pretty sure even with the anti-lockout you can still have sshguard block your IP.. The rule just makes sure the ports are open.. I don't believe it disables wrong passwords from locking the IP for a specific amount of time

          That is why you can add Ips to never lock out

          lock.jpg

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          F 1 Reply Last reply Reply Quote 1
          • F
            furom @johnpoz
            last edited by

            @johnpoz Agreed, that seems good when debugging, but hardly something for a production system?

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @furom
              last edited by

              @furom hmmm? What do you mean - I have my IP in there.. Just in case - your sleepy, or you have caps lock on or something.. I have password saved, and use publickey to auth so I never send the wrong password anyway. But if you want to make sure you don't lock your IP because of typo's why would you not put in the IP of box you admin from?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              F 1 Reply Last reply Reply Quote 1
              • F
                furom @johnpoz
                last edited by

                @johnpoz I guess you're right, it probably does more good than anything else. I just think a firewall of all things is a place where protection should not be bypassed. I am having my cut of strangeness on mine so perhaps I'm a little too cautious. Not much "just works" on my box. Not even simple SSH keys... :( It console prompt just hungs when trying it. and nothing in the log, so no block...

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  It hangs at the client trying to connect? Times out eventually?

                  Can you still access the pfSense webgui after that?

                  F 1 Reply Last reply Reply Quote 0
                  • F
                    furom @stephenw10
                    last edited by

                    @stephenw10 said in GUI Lockout?!:

                    It hangs at the client trying to connect? Times out eventually?

                    Can you still access the pfSense webgui after that?

                    Not for minutes at least. I am connected via webgui, so works, yes.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Ah, I see this could be the result of the duplicate user groups issue you also hit. I would resolve that first before digging any further here.

                      F 1 Reply Last reply Reply Quote 1
                      • F
                        furom @stephenw10
                        last edited by

                        @stephenw10 said in GUI Lockout?!:

                        Ah, I see this could be the result of the duplicate user groups issue you also hit. I would resolve that first before digging any further here.

                        Thanks, I just finished typing in everything manually and somehow got DNS working too.. I hope there will be a limited number of rabbit holes ahead, I need it to "just work" for a while now... :P

                        I will try adding the SSH key tomorrow, with all that has been, just a tiny bit worried it won't work... :/

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.