Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't acces WebGUI from the WAN, even though there is a rule for it

    webGUI
    4
    9
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mwilhelm91
      last edited by

      Hey there,

      I have the problem that I can't access the WebGUI from the WAN, even though I have configured a firewall rule that should it allow it.

      The rule:

      Action: Pass
      Interface: WAN
      Address Familiy: IPv4+IPv6
      Protocol: TCP
      Source: any
      Destination: WAN address
      Port Range: HTTPS(443)

      The only way I can connect to the WebGUI from the WAN is by disabling the firewall rules per shell with pfctl -d. As soon as I enable the rule I can't access the WebGUI.

      I really don't know what to do here, because all tips I found say you have to make the rule I already implemented.

      Any help would be appreciated.

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        Hi,

        Your WAN is directly connected to the net ? (what is the WAN interface IP ?)

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • K
          kejianshi
          last edited by

          Probably need to uncheck the "block private" on the wan interface.

          1 Reply Last reply Reply Quote 0
          • M
            mwilhelm91
            last edited by

            The pfSense OS is running on a VM. I want to access from the internal network, the WAN interface is connected to it (some private IP address). I already unchecked the blocking of private IPs, so that's sadly not the problem.

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              When you say "internal" network, can you elaborate?

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                @mwilhelm91:

                The pfSense OS is running on a VM…..

                So it's more a VM issue (VM setup).
                That explains … your rule is ok, I used the same in the past.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by

                  I have one for test running as VM and allowing access via the WAN works fine, so I'm wondering about your rules being used on the WAN.  I'm pretty sure I put a "pass all" rule there, since nothing is going to reach the wan unless I allow it anyway.  Its labeled wrong.  I initially tried to pass HTTPS as you did and it was failing so I passed all and it worked.  Not a security issue for me since it is firewalled by a physical pfsense.

                  ![Firewall Rule.png](/public/imported_attachments/1/Firewall Rule.png)
                  ![Firewall Rule.png_thumb](/public/imported_attachments/1/Firewall Rule.png_thumb)

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    What?  You are suggesting someone put a any any rule on their wan?  That is some bad advice… Reader please do not do this!!  No matter what sort of setup you have.. Unless really are your wanting to do with pfsense is just route.. If so then turn off nat..

                    If those are your wan rules, and your webgui is listening on 443 then that would work.. Please post a picture of your want rules.  Do you have any rules in floating?  Please show your webgui listening on 443..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by

                      I assume his isn't connected to the web?  If so, port forwarding to the gui would also be insane.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.