Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Web GUI from WAN IP inside LAN is this normal?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 4 Posters 238 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      austin.bard
      last edited by

      Hello all simple question as I am paranoid about what this means. To start off with I have no WAN Firewall rules set. But I am able to access my Webgui from inside my LAN by typing in my WAN IP. Is this normal? Is there a setting I can switch this off at? I have tried accessing the IP from a remote computer and it does not complete as I would expect. Just looking to make sure, thanks!

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Is this normal?

        Yes.

        Is there a setting I can switch this off at?

        No.  It simply hits the same endpoint via LAN instead.

        I have tried accessing the IP from a remote computer and it does not complete as I would expect.

        Do all testing from WAN, not LAN.

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott
          last edited by

          One other point.  The filtering that would block this is done on the WAN interface.  You are not passing through it, even when connecting to the WAN address from the LAN side.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Lets look at it this way… Lets say your wan IP is 1.2.3.4

            What is the default lan rules?  Any Any right!  So is 1.2.3.4 fall into ANY?  If so then yes the lan would be able to access it.

            Rules are evaluated as traffic enters that interface from the network its connected too, first rule to trigger wins no other rules are evaluated.  So when you have some client on 192.168.1.X for example on your lan wanting to go to 1.2.3.4:443 that falls in the rule any any - so yes it is allowed.

            If you do not want to be able to hit the wan IP from your lan - then put in a rule that blocks that on your lan... But seems kind of pointless since your allowing lan your web gui on the lan address via the anti lockout rule.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.