Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot ssh into pfSense at WAN interface

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 5 Posters 447 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @kwangmien
      last edited by

      @kwangmien
      Did you add a firewall rule to allow SSH to the WAN address?

      K 1 Reply Last reply Reply Quote 0
      • E
        elvisimprsntr @kwangmien
        last edited by elvisimprsntr

        @kwangmien

        Allowing SSH port 22 access via the WAN side is a recipe to be hacked.

        Don't be a potential victim. Use a VPN instead.

        T K V 3 Replies Last reply Reply Quote 0
        • T
          Troutpocket @elvisimprsntr
          last edited by

          @elvisimprsntr Very good advice...

          Alternatively, you can source limit to a single IP or hostname to prevent random IPs filling your secure logs with ssh login attempts.

          But definitely don't expose SSH (or any admin interface) to the internet at large. We don't even allow it on the corp/guest vlans. 22, 80, 443 on "this firewall" is only accessible via the management LAN.

          K 1 Reply Last reply Reply Quote 0
          • K
            kwangmien @viragomann
            last edited by

            @viragomann after setting a rule to allow SSH , i can now ssh in.

            1 Reply Last reply Reply Quote 0
            • K
              kwangmien @elvisimprsntr
              last edited by

              @elvisimprsntr Thanks for the advice. I am actually new to pfSense and testing the SSH at WAN interface.

              1 Reply Last reply Reply Quote 0
              • K
                kwangmien @Troutpocket
                last edited by

                @Troutpocket Thanks for the advice.

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann @elvisimprsntr
                  last edited by

                  @elvisimprsntr
                  I use SSH with password + public key authorization. I don't think, that this is really less secure than a VPN.
                  VPN just provides an additional authorization layer.

                  T E 2 Replies Last reply Reply Quote 0
                  • T
                    Troutpocket @viragomann
                    last edited by

                    @viragomann I'd argue it's better. I still recommend source-restricting SSH just to keep your log file size down. In any case, if you're going to use a VPN then seriously consider adding MFA. There's good integration with Google Auth, DUO, and MS Entra via RADIUS auth. If (when?) OpenVPN is compromised like some of the commercial SSL vpns then hopefully MFA will save you.

                    1 Reply Last reply Reply Quote 0
                    • E
                      elvisimprsntr @viragomann
                      last edited by

                      @viragomann said in Cannot ssh into pfSense at WAN interface:

                      @elvisimprsntr
                      I use SSH with password + public key authorization. I don't think, that this is really less secure than a VPN.
                      VPN just provides an additional authorization layer.

                      That assumes there is not a vulnerability which the attacker can bypass authentication.

                      Examples of SSH vulnerabilities which apply to pfSense.

                      https://nvd.nist.gov/vuln/detail/CVE-2024-6387
                      https://terrapin-attack.com

                      Its your decision.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Yup I would always set a limited source for that.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.