Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Change the LAN firewalling

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 4 Posters 4.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? This user is from outside of this forum
      Guest
      last edited by

      Hi,

      • I did a mistake : i disabled by error all the traffics in the LAN subnet.
        Is it possible to change a rule in the LAN by the command line ? You know re-enable again the traffics without doing a reset…

      • Is it possible to restart a service by the commande line like IPSec ?
        Perhaps just killing the racoon pid... ?

      Thank you in advance for your return.

      ++

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        Why not just log in and create a new rule allowing traffic again?

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • ? This user is from outside of this forum
          Guest
          last edited by

          Well, it seemed that i wasn't able to access by http protocole…
          I'll check by rebooting once again.

          1 Reply Last reply Reply Quote 0
          • E Offline
            Efonnes
            last edited by

            If you've disabled the web gui anti-lockout rule for LAN, I think you can re-enable it by setting the LAN IP address from the console.

            1 Reply Last reply Reply Quote 0
            • ? This user is from outside of this forum
              Guest
              last edited by

              If you've disabled the web gui anti-lockout rule for LAN,

              But how could i disable it since right now, i can't access to the web interface ?

              the rule disable all traffics in the LAN…

              1 Reply Last reply Reply Quote 0
              • ? This user is from outside of this forum
                Guest
                last edited by

                Blocked access with firewall rules

                If you blocked yourself out of the WebGUI remotely with a firewall rule, there may still be hope. This shouldn't happen from the LAN as there should be an anti-lockout rule that maintains access to the WebGUI from that interface.

                Having to walk someone on-site through fixing the rule is better than losing everything!

                Well, i can't access from the LAN…

                Is is possible to disable the rule for the LAN interface by the console ?

                Thank you in advance.

                ++

                1 Reply Last reply Reply Quote 0
                • GruensFroeschliG Offline
                  GruensFroeschli
                  last edited by

                  @Efonne:

                  If you've disabled the web gui anti-lockout rule for LAN, I think you can re-enable it by setting the LAN IP address from the console.

                  ↑

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  • ? This user is from outside of this forum
                    Guest
                    last edited by

                    If you've disabled the web gui anti-lockout rule for LAN, I think you can re-enable it by setting the LAN IP address from the console.

                    ??? Well i don't really understand… ???

                    I did not disable "the web gui anti-lockout rule for LAN".
                    I did make a rule on the firewall configuration that disable all traffics from the LAN.

                    I've tried to set the LAN IP address with the console but i still can not access.

                    I did disable the firewall :

                    pfctl -d
                    

                    But i still can't access to the webgui.

                    With which command could i modify the /tmp/rules.debug file, please ?
                    I tried emacs, vim, nano but these commands do not existe.

                    ++

                    1 Reply Last reply Reply Quote 0
                    • ? This user is from outside of this forum
                      Guest
                      last edited by

                      I found "ee" command to edit a file.

                      1 Reply Last reply Reply Quote 0
                      • ? This user is from outside of this forum
                        Guest
                        last edited by

                        Well i can now edit /tmp/rules.debug but i can not find my "rule" that block all the LAN traffics…

                        I'm still blocked...

                        1 Reply Last reply Reply Quote 0
                        • K Offline
                          kpa
                          last edited by

                          You don't have to edit anything, just do what Efonne told you, reset the LAN address using option 2) in the console menu.

                          1 Reply Last reply Reply Quote 0
                          • E Offline
                            Efonnes
                            last edited by

                            If you want to do it by manually editing /tmp/rules.debug anyway, run pfctl -o basic -f /tmp/rules.debug after you are done to reload the rules.

                            1 Reply Last reply Reply Quote 0
                            • ? This user is from outside of this forum
                              Guest
                              last edited by

                              @kpa:

                              You don't have to edit anything, just do what Efonne told you, reset the LAN address using option 2) in the console menu.

                              Just said, i did this action several time.
                              And i connected to the LAN interface directly to access but i did not success…

                              1 Reply Last reply Reply Quote 0
                              • ? This user is from outside of this forum
                                Guest
                                last edited by

                                Well, my apologies.
                                It seems that's re-enable the set up of the LAN does resolve the problem.

                                I had some ethernet cable trouble…

                                Thanks again for your help.
                                ++

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.