Access WebGUI from OPT (management interfaces)
-
Hi,
I have setup a management interface on my pFsense router. It goes like this:WAN => igb0
LAN => igb1 100.64.0.1
MGNT => re0 192.168.99.8I can access the webgui from LAN. But when I tried from MGNT, it just timeout. I did set up firewall rules for the MGNT interface, at the begining I just let port 8443 and 22 and ICMP.
From my computer I can ping 192.168.99.8, I also can logon with SSH. I see in the log that connection to 192.168.99.8:8443 are allowed, but the webpages aren't serve? Is that normal? Do I need to add a virtual host in the webserver settings to make it work. I'm I missing something?
Thanks for your help.
-
You need a firewall rule on MGNT to allow you to hit the GUI port.
-
Hi thanks for the quick answer,
I did put a rule for the management port that allow anything, it's full open! I can see that the connection pass the firewall and accepted in the logs. As I mention, I can connect through SSH. But the webserver timeout all the time. -
are you sure the port is 8443 ? this is not ipcop :)
-
Hi, @kiokoman, that the right port, it's the way I set it up. I can access the webgui on the LAN interface on that port. On my computer I have 2 NIC one to access the normal LAN and one dedicated to management, which I use to connect to all my networking equipement and servers.
My goal is to not allowed connection to the webgui from the LAN, only from the managment. Right now, the webgui is only accessible from the LAN and when I try from the management, it time out. I wonder why I cannot access the webgui from another interface?
-
Management rules:
https://imgur.com/puzJTnj
LAN Rules
https://imgur.com/wC0sfqmMGNT Log:
https://imgur.com/ibjmDw0 -
pls show us how you configure the interface with a screenshot
-
@kiokoman Just found the problem... Layer 8, problem, I configure port 8433 instead of 8443, so when I tried to connect with 192.168.99.8:8443, well it wasn't working for obvious reason!
Sometime when you are to close from the forest, vision get fuzzy!
THanks for your help!
-
I'm pretty sure I asked if ....
glad you solved -
@kiokoman Yes you did! I was blinded by it I guess!