Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Web GUI Access from Internet

    Scheduled Pinned Locked Moved Firewalling
    35 Posts 4 Posters 3.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kejianshi
      last edited by

      I just had a really bad sneaking suspicion that I just have to ask…

      What is the WAN of the pfsense hooked up to?

      If pfsense is plugged into a MODEM (not a router) and the ISP isn't blocking 443 this should already be working.

      If this is plugged into a ROUTER or a COMBO modem router and your pfsense is showing some private IP (like 192.168.x.x) on the WAN interface in the gui, this isn't going to be so simple.

      1 Reply Last reply Reply Quote 0
      • C
        cpatte7372
        last edited by

        Kej

        I'm not actually on some other computer… I'm on my own computer that has internet access. However, my pfSense has been deployed on ESXi host.

        pfSense has a public ip address as well as a LAN address.

        I can connect via LAN but can't connect via WAN. I know the pfSense WAN interface is configured corrected with a public ip address because I can ping 8.8.8.8 and any other public ip address from pfSense interface.

        Cheers

        1 Reply Last reply Reply Quote 0
        • K
          kejianshi
          last edited by

          Does "my own computer" have a different public IP than pfsense wan?

          You can always PM me your public IP and I can try it from here….

          1 Reply Last reply Reply Quote 0
          • C
            cpatte7372
            last edited by

            'My own computer', has an ip address assigned to by Virgin Media of 192.168.0.1.

            So basically, what I'm trying to do is access my pfsense firewall from any computer that has an internet connection

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              If you PM me your public IP that pfsense is on, I will see if I get a GUI interface from here.

              (NOTE - I don't actually think this is a good idea, but for the sake of testing, I'd do it)

              1 Reply Last reply Reply Quote 0
              • C
                cpatte7372
                last edited by

                Kej

                I hope you're on the level - PM sent

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by

                  Not working - How are you determining your public IP?

                  1 Reply Last reply Reply Quote 0
                  • C
                    cpatte7372
                    last edited by

                    I configured it when I deployed it with ESXi host

                    see image

                    pf1.PNG
                    pf1.PNG_thumb

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by

                      And are you sure it is working?

                      Can you please show the main pfsense gui?

                      The part where it talks about version under system information?

                      Does it say "you are on the latest release" or some other message?

                      1 Reply Last reply Reply Quote 0
                      • C
                        cpatte7372
                        last edited by

                        Do you mean

                        asa.PNG
                        asa.PNG_thumb

                        1 Reply Last reply Reply Quote 0
                        • C
                          cpatte7372
                          last edited by

                          Or do you mean

                          asa.PNG
                          asa.PNG_thumb

                          1 Reply Last reply Reply Quote 0
                          • K
                            kejianshi
                            last edited by

                            No - I mean the first thing that pops up when you go to https://192.168.1.1

                            left side of screen
                            Version.

                            1 Reply Last reply Reply Quote 0
                            • K
                              kejianshi
                              last edited by

                              I have to sleep, so here is what you need to verify - pfsense can see the internet and also be seen.

                              1 Reply Last reply Reply Quote 0
                              • C
                                cpatte7372
                                last edited by

                                Here you go

                                asa.PNG
                                asa.PNG_thumb

                                1 Reply Last reply Reply Quote 0
                                • C
                                  cpatte7372
                                  last edited by

                                  Anybody else can help while Kej gets some Zzzzzzzzzz?

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    cpatte7372
                                    last edited by

                                    Just so you, when I turn off firewall, see below I can connect to pfsense with http://pfsense public ip address.

                                    Therefore, I need to create a firewall rule to allow access when the firewall is enabled….

                                    Can you help with that?

                                    asa.PNG
                                    asa.PNG_thumb

                                    1 Reply Last reply Reply Quote 0
                                    • chpalmerC
                                      chpalmer
                                      last edited by

                                      You do not need to port forward to your LAN address.

                                      Making a WAN rule to your WAN Address will work much easier.

                                      Go back to my first post and try what I said.  Delete any port forwarding you have done with your GUI port (I assume 443)

                                      I do this with every firewall I put in until I test the VPN from my location here.

                                      Triggering snowflakes one by one..
                                      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                      1 Reply Last reply Reply Quote 0
                                      • chpalmerC
                                        chpalmer
                                        last edited by

                                        https://forum.pfsense.org/index.php?topic=86709.0

                                        https://forum.pfsense.org/index.php?topic=86838.msg476382#msg476382    This one you state you made it work on port 80…

                                        :o

                                        Triggering snowflakes one by one..
                                        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                        1 Reply Last reply Reply Quote 0
                                        • C
                                          cpatte7372
                                          last edited by

                                          chpalmer,

                                          Thanks for responding.

                                          I will implement your suggestion

                                          Cheers

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.