Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Sign in site publicly available

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 5 Posters 858 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      adfhaerhad
      last edited by

      Sorry for the noob question, but how do I prevent access to the pfsense sign in page from the Internet?
      I've tried two different rules, one an alias to the url and one as destination "this firewall", but both are still publicly accessible.
      I just want to block https, nothing else.

      1 Reply Last reply Reply Quote 0
      • pttP Offline
        ptt Rebel Alliance
        last edited by

        https://forum.pfsense.org/index.php?topic=140143.msg765747#msg765747

        Please "show us" (screenshot)  your WAN FW rules

        1 Reply Last reply Reply Quote 0
        • A Offline
          adfhaerhad
          last edited by

          I followed this post:
          https://doc.pfsense.org/index.php/Restrict_access_to_management_interface
          but when I enter in my domain, I'm still able to reach the pfsense log in page.

          So now I have 4 firewall rules, 2 on LAN & 2 on WAN.
          WAN is block access to the domain name.
          LAN is permit 1 internal IP & block all else to the destination of "This Firewall"

          Any ideas?

          1 Reply Last reply Reply Quote 0
          • pttP Offline
            ptt Rebel Alliance
            last edited by

            How & from where are you "testing" ?

            Please "show us" (screenshot)  your WAN FW rules

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              Post up your rules… You can say you did XYZ.. Doesn't mean that is what you actually did.. only that you think you did that.. Most come mistake is not understanding that rules are evaluated top down first rule wins, no other rules are evaluated..

              So blocking access to anything below a any any allow rule wouldn't do a thing..

              So please post up you rules on your wan and your lan.. And are you using a proxy, etc.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

              1 Reply Last reply Reply Quote 0
              • G Offline
                GoldFish
                last edited by

                @johnpoz:

                Post up your rules… You can say you did XYZ.. Doesn't mean that is what you actually did.. only that you think you did that.. Most come mistake is not understanding that rules are evaluated top down first rule wins, no other rules are evaluated..

                So blocking access to anything below a any any allow rule wouldn't do a thing..

                So please post up you rules on your wan and your lan.. And are you using a proxy, etc.

                I agree. Recently i allowed home management access on WAN only from my office IP. If you follow Johnpoz's steps you should be fine

                • pfSense Enthusiast *
                1 Reply Last reply Reply Quote 0
                • chpalmerC Offline
                  chpalmer
                  last edited by

                  He's probably trying from his LAN, which of coarse by default would allow access..

                  Triggering snowflakes one by one..
                  Primary- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+
                  Lab Unit- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Agreed why can I hit my wan IP from my lan is a question that comes up like daily ;)

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.