Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NEW WAN port has anti-lockout firewall rule, Why?

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 3 Posters 908 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rcoleman-netgate Netgate @sawilson
      last edited by

      @sawilson said in NEW WAN port has anti-lockout firewall rule, Why?:

      Yes it was

      That is why.

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      1 Reply Last reply Reply Quote 0
      • S Offline
        sawilson
        last edited by

        So how do I fix it? Any suggestions?

        R 1 Reply Last reply Reply Quote 0
        • R Offline
          rcoleman-netgate Netgate @sawilson
          last edited by

          @sawilson Delete the interface completely and re-create it is the most effective way to remove the rule...

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          R 1 Reply Last reply Reply Quote 0
          • R Offline
            rcoleman-netgate Netgate @rcoleman-netgate
            last edited by

            Also there's a System menu setting for it. ๐Ÿ˜„

            Ryan
            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
            Requesting firmware for your Netgate device? https://go.netgate.com
            Switching: Mikrotik, Netgear, Extreme
            Wireless: Aruba, Ubiquiti

            1 Reply Last reply Reply Quote 0
            • S Offline
              SteveITS Rebel Alliance @sawilson
              last edited by

              @sawilson said in NEW WAN port has anti-lockout firewall rule, Why?:

              add my own entries for anti-lockout and check the box to stop the auto entries, which is doable but I wonder if it will pickup and delete this problem item

              You can definitely create your own rules. I was going to suggest unchecking the system setting box, and checking it again, to see if it moves. Interesting though, on that screen it specifically mentions LAN, and you do not have an interface named LAN correct?

              The 60 K on the rule indicates some traffic has matched the rule.

              Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
              Upvote ๐Ÿ‘ helpful posts!

              1 Reply Last reply Reply Quote 0
              • S Offline
                sawilson
                last edited by

                Ryan,

                Tried deleting the interface and re-adding it. The entries come back.

                As far as the system setting, as I previously asked, One idea I had was to add my own entries for anti-lockout and check the system box to stop the auto entries, which is doable but I wonder if it will pickup and delete this problem item on a WAN port (the description for the entry only speaks of LAN ports). Maybe I'd have to change it back to LAN temporarily????

                S.

                R 1 Reply Last reply Reply Quote 0
                • S Offline
                  sawilson
                  last edited by

                  Steve,

                  The system setting is unchecked to create the entries and checked to stop it. LAN, as I understand it is the type of interface rather than the name. It should obviously ONLY create this auto entry for LAN and never for WAN. This interface was LAN but now is WAN but these anti-lockout firewall entries seem to be "sticky", there even after deleting and reconfiguring the interface.

                  I'm leaning towards creating my own entries and checking the box to see if that fixes it.

                  S.

                  S 1 Reply Last reply Reply Quote 0
                  • R Offline
                    rcoleman-netgate Netgate @sawilson
                    last edited by

                    @sawilson said in NEW WAN port has anti-lockout firewall rule, Why?:

                    The entries come back.

                    @rcoleman-netgate said in NEW WAN port has anti-lockout firewall rule, Why?:

                    Also there's a System menu setting for it.

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      SteveITS Rebel Alliance @sawilson
                      last edited by SteveITS

                      @sawilson Sorry if I wrote it backwards. I meant, toggle it the other way, then back again.

                      It doesn't create them for all LANs (interfaces without a gateway), for example our office doesn't have it for our lab network. So it might actually be tied to the name LAN...? (edit: or in your case what was LAN, if it saved the interface the first time around)

                      Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                      Upvote ๐Ÿ‘ helpful posts!

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        sawilson
                        last edited by

                        Steve and to All,

                        Steve: I see what you're saying, I have 4 "LAN" ports and it only added the rule to one, maybe it just does it during the install to the default LAN port. I guess the idea is of the auto entry is to make sure you have access to configure initially and the rest is up to you.

                        I actually had added my own pass entries previously, so I just ticked the box in system and Voila! they went away.

                        Thanks everyone for your help and suggestions,
                        Scott

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.