Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Lockedout LAN ? Huh ??

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      msvuze
      last edited by

      I changed the LAN login for pfsense from the default https port to another port.
      I also enabled Block private networks and Enabled Block bogon networks but my local address starts as 192.168..

      I am now locked out of the webgui!

      I have physical access to the firewall via serial port/putty.

      How can I do the following:

      1. Disable "block private networks"
      2. Disable "block bogon networks"

      via shell and I should be able to get back via webgui, I hope.

      Thanks in-advance for any help

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        "I also enabled Block private networks and Enabled Block bogon networks but my local address starts as 192.168.."

        Why would you have don't that???

        Did you also turn off the antilockout rule?  This rule is there to keep you from locking yourself out like that..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

        1 Reply Last reply Reply Quote 0
        • M Offline
          msvuze
          last edited by

          @johnpoz:

          "I also enabled Block private networks and Enabled Block bogon networks but my local address starts as 192.168.."

          Why would you have don't that???

          Did you also turn off the antilockout rule?  This rule is there to keep you from locking yourself out like that..

          Because I'm an idiot and a total noob! I changed the port for the https login but I forgot to update the port in the anti-lockout firewall rule.
          How it happened was I was reading this tutorial I found on how to add another pfsense box to setup an HA, and somewhere I messed up big time.
          I then found out I need 3 static ip's and I dont even have one static ip, I have a cable connection at home and wanted to setup the 2nd box for failover  :( :(

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            It would auto update to the ports your using for your gui in the autolock rule..

            Worse case at the console just reset it to factory..

            reset.png
            reset.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

            1 Reply Last reply Reply Quote 0
            • M Offline
              msvuze
              last edited by

              @johnpoz:

              It would auto update to the ports your using for your gui in the autolock rule..

              Then I just need to:

              1. Disable "block private networks"
              2. Disable "block bogon networks"

              via shell, but how do I do this ?

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                if your antilock rule is working it would be above those rules and would allow you in…

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                1 Reply Last reply Reply Quote 0
                • H Offline
                  hda
                  last edited by

                  "When this is unchecked, access to the webConfigurator on the LAN interface is always permitted, regardless of the user-defined firewall rule set. Check this box to disable this automatically added rule, so access to the webConfigurator is controlled by the user-defined firewall rules (ensure a firewall rule is in place that allows access, to avoid being locked out!)

                  Hint: the "Set interface(s) IP address" option in the console menu resets this setting as well."

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    msvuze
                    last edited by

                    @johnpoz:

                    if your antilock rule is working it would be above those rules and would allow you in…

                    So is it possible to add a firewall rule to allow everything on a LAN ?
                    like:```
                    easyrule pass LAN tcp 192.168.1.2 192.168.3.200 any

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      msvuze
                      last edited by

                      @hda:

                      "When this is unchecked, access to the webConfigurator on the LAN interface is always permitted, regardless of the user-defined firewall rule set. Check this box to disable this automatically added rule, so access to the webConfigurator is controlled by the user-defined firewall rules (ensure a firewall rule is in place that allows access, to avoid being locked out!)

                      Hint: the "Set interface(s) IP address" option in the console menu resets this setting as well."

                      So if I Set interface(s) IP address to the same IP address that I had it will reset the "block private networks" and "block bogon networks" to their defaults ??? SWEET!!

                      I will try this went I get home, thanks

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.