Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Open Ports

    OpenVPN
    2
    16
    4.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dgeorge
      last edited by

      Update:  Put cable modem/router back into gateway mode and still getting port 80 and 443 open  on grc.com when openvpn client is running.  All ports are fine without openvpn.

      How do I disable remote management access?

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        I would leave it in Bridge mode myself…

        I seriously doubt anyone can see your pfsense gui from the outside if you haven't allowed it.

        Your modems gui might be another story.  Who is your ISP?

        Ask someone you know to try and access your IP address with a browser and see what they get.

        Good Luck!

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • D
          dgeorge
          last edited by

          Just checked myself with my cell phone on the cell network (not wifi) and up popped the pfsense login screen!
          Im on Rogers in Canada.

          Need to get this fixed before I can use this.  How do I disable remote access?

          1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer
            last edited by

            Can you post a screenshot of your WAN firewall rules?

            Is your phone connected to the same VPN?

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            1 Reply Last reply Reply Quote 0
            • D
              dgeorge
              last edited by

              Cell phone was not on the vpn or the wifi.  Checked using lte network
              Lets hope this works…......attaching....... :)

              ![WAN rules.jpg](/public/imported_attachments/1/WAN rules.jpg)
              ![WAN rules.jpg_thumb](/public/imported_attachments/1/WAN rules.jpg_thumb)

              1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer
                last edited by

                Yep that worked.

                And as I thought.  You have the entire world allowed to see everything.

                You need to turn that rule off.

                What are you attempting to give the world WAN access to?

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                1 Reply Last reply Reply Quote 0
                • D
                  dgeorge
                  last edited by

                  I think I saw that rule in another guide and added it to see if it helped.
                  Deleted it and rebooted but still seeing port 80 and 443 open

                  1 Reply Last reply Reply Quote 0
                  • chpalmerC
                    chpalmer
                    last edited by

                    VPN rule?
                    Im wiress for a bit. But this sound like you have a vpn firewall rule thats set to any.

                    Triggering snowflakes one by one..
                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                    1 Reply Last reply Reply Quote 0
                    • D
                      dgeorge
                      last edited by

                      The wan rule you said should be deleted.  I want to route all traffic through the VPN to my VPN provider.

                      1 Reply Last reply Reply Quote 0
                      • chpalmerC
                        chpalmer
                        last edited by

                        Yep understood.  VPN rules are also incoming. Shut any off.

                        Triggering snowflakes one by one..
                        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                        1 Reply Last reply Reply Quote 0
                        • D
                          dgeorge
                          last edited by

                          Great success! (in my best Borat voice)

                          Looks like that fixed it.  I'll give it a reboot to make sure and post back.

                          Thank you!

                          1 Reply Last reply Reply Quote 0
                          • D
                            dgeorge
                            last edited by

                            Looks like its sticking.

                            Thanks again for your help chpalmer.  Now I can enjoy my weekend!

                            1 Reply Last reply Reply Quote 0
                            • chpalmerC
                              chpalmer
                              last edited by

                              Congrats!

                              Keep in mind that rules on an interface are incoming to that interface.  By making an "any" to "any" rule on WAN or VPN you let anything through to anything.  ( this took me a few times to get across to myself…)

                              For a box only dealing with clients on the lan side and no servers (no reason to allow someone on the outside acess to the inside) there should never be any rules for other than the LAN interface.

                              Triggering snowflakes one by one..
                              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.