Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to setup HTTPS between my browser and my pfSense firewall?

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 4 Posters 784 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      flugenblar
      last edited by

      Newbie here. I just installed a pfSense firewall, running v2.7.2. It works great! This is for my home office. I can aim my Google Chrome browser at 192.168.1.1 no problem, and logon, but the connection itself is simple HTTP, not HTTPS. How do configure the firewall & browser to use HTTPS? I'm sure this is simple every day topic, just don't know where to look. All help will be greatly appreciated.

      keyserK 1 Reply Last reply Reply Quote 0
      • keyserK
        keyser Rebel Alliance @flugenblar
        last edited by

        @flugenblar SYSTEM -> ADVANCED -> ADMIN ACCESS

        Love the no fuss of using the official appliances :-)

        F 1 Reply Last reply Reply Quote 1
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Yup that ^.

          It should use https (and redirect http to https) by default though.

          1 Reply Last reply Reply Quote 0
          • F
            flugenblar @keyser
            last edited by

            @keyser

            I've got it set to HTTPS and the SSL/TLS certificate is set to GUI Default (long number)... I didn't set that it was set by default, but I still see Not Secure in the URL box of my Chrome browser. Could Chrome by trying to warn me about a self-signed certificate? I think this is using a self-signed cert, maybe it's just saying it shoudn't be trusted?

            johnpozJ F 2 Replies Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Yes, it uses a self-signed cert by default.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @flugenblar
                last edited by johnpoz

                @flugenblar said in How to setup HTTPS between my browser and my pfSense firewall?:

                I think this is using a self-signed cert

                If you didn't create your own cert with CA your browser trusts, then yeah its going to warn you.

                here I created my own ca in pfsense, then issued certs from that CA, and my browser trusts my CA.. But still notifies me that hey we trust this but not a built in normal firefox CA

                example.jpg

                Another option would be use acme cert, then your browser wont bitch at you.. But you need to use a public domain. Which a cert you sign with your own ca you can use any fqdn you want, notice mine is using home.arpa the new recommended local domain. And you can add rfc1918 address space..

                See I can access with IP and no warning..

                here even in chrome

                chrome.jpg

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                F 1 Reply Last reply Reply Quote 0
                • F
                  flugenblar @flugenblar
                  last edited by

                  @flugenblar

                  when I use Safari, I get a warning too. it says:

                  pfSense-65922812c2462
                  Self-signed root certificate
                  Expires: Saturday, February 1, 2025 at 6:48:15 PM Pacific Standard Time
                  ! This certificate has not been verified by a third part

                  ...
                  Organization pfSense GUI default Self-signed Certificate
                  Common Name pfSense-65922812c2462
                  ...

                  so should I try to refresh the cert or get a new one or something? or just live with the warning? I mean, I setup the hardware and installed the image, so i do actually trust it... but...

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @flugenblar
                    last edited by johnpoz

                    @flugenblar browsers are most always going to complain about self signed certs.. If you want the warning to go away you going to have to create your own CA, issue cert and have your browser trust it.

                    or use domain and the acme (packet to use lets encrypt) to get a cert for for some domain to have your web gui use..

                    I have gone over how to create a CA and issue cert your browser will trust many times... Here is a old thread where I went over it

                    https://forum.netgate.com/post/827060

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 1
                    • F
                      flugenblar @johnpoz
                      last edited by

                      @johnpoz Thanks! that all makes sense. if i were doing this at work I'd be able to go to the team that issues certs and get one for this, but I'm at home and dont want to go through all that business. I might play with creating my own CA in pfSense. Not sure I care that much yet, but it's an interesting option.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @flugenblar
                        last edited by johnpoz

                        @flugenblar yeah as long as your browser doesn't bug you every time about the self signed, its not an issue for sure.. Your still encrypting your traffic..

                        Its only a few seconds to setup, and once you setup a browser to trust you can issue signed certs for all your different things that might want to use a cert. switches, printers, your nas gui, my unifi controller software.. etc. etc.

                        Use to be better when the browsers also didn't complain about lifetime of cert, use to issue them for 10 years and never had to think about it again etc.. But now I think like 398 days is longest you can issue one for before browsers bitch at you about it.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.