Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Resetting while connected to WAN (sg 2440) –> security risk?

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    5 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hopeless_noob
      last edited by

      I played around with my new pfsense box (sg 2440) and locked myself out of the web-ui. I tried to use the reset button but it did not work the first two attempts because I didn't pressed it long enough. I finally got it reset and working again. However, I cannot remember anymore whether I actually disconnected the pfsense box from the modem/wan while trying to reset the pfsense box(successfully and unsuccessfully).
      So here is my question: Does playing around with the reset button (successful or unsuccessful reset) while being connected to the WAN (or LAN) put one at an increased risk of being hacked? I am talking about the pfsense box itself (vulnerabilities during the boot sequence?) and the internal network (pfsense not filtering traffic while resetting?)?
      If so, should I rather consider installing pfsense from scratch?

      Any feedback is much appreciated

      1 Reply Last reply Reply Quote 0
      • F Offline
        fredfred5
        last edited by

        Not really, the WAN interface isn't activated until near the end of the boot sequence so it wont be connected to the Internet while booting. Same goes for the LAN, it wont be passing any traffic at all until pfSense has finished booting.

        FYI this is how to perform a factory reset using the reset button:

        Youtube Video

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          And the default configuration of firewall rules on WAN is deny all inbound.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • H Offline
            hopeless_noob
            last edited by

            Thanks so much for the replies to both of you. Indeed I ended up watching the exact same youtube video which helped a lot ;-)

            1 Reply Last reply Reply Quote 0
            • N Offline
              NOYB
              last edited by

              There is a period of time during the startup of pfSense, between when an interface is being activated, i.e. "Configuring *** Interface…" and when the firewall rules are applied, i.e. "Configuring firewall......done" in which the system is wide open.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.