Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Brand new way to be locked out :)

    IPsec
    2
    3
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mbouchonnet
      last edited by

      Hello,

      I wanted to share my find with you.
      I have found a way to be locked out of the web gui and the ssh not already listed here :
      https://doc.pfsense.org/index.php/Locked_out_of_the_WebGUI

      I was trying to make my vpn tunnel works and wanted to see if it would change anything to go to VPN: IPsec: Edit Phase 2 and to change the mode from Tunnel IPV4 to Transport.
      I actually changed a lot of things :p
      I got disconnected from the web gui, was unable to come back and to open an ssh connection from the Wan.
      Flushing the firewall rules did nothing.
      Killing the racoon process did nothing either.
      As an ipsec (and BSD) noob, i managed to gain access with elinks on the LAN and selected Disable this phase2 entry.

      If anyone has an idea of what could I have done on the CLI to regain access i'm interested.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If the Phase 1 was between the WAN IP of the firewall and the IP address you were coming from, then transport mode would have tried to encrypt all traffic between those two addresses, which sounds like what was happening.

        Had the tunnel connected, you may not have even noticed a problem.

        Not sure I'd consider that a scenario to go on the page, since it would work from any other public address.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M
          mbouchonnet
          last edited by

          @jimp:

          If the Phase 1 was between the WAN IP of the firewall and the IP address you were coming from

          Yes, good guess, I didn't think of it while trying to regain access.
          It might be a good idea to (at least) add a line somewhere about "changing ip address".
          It would too resolve "5 Locked Out by Too Many Failed Login Attempts"

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.