• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How disable webgui … if possible

Scheduled Pinned Locked Moved webGUI
14 Posts 7 Posters 13.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    LiquiD_85
    last edited by Jul 13, 2009, 9:16 AM

    Uhmmm … NO :D:D:D i'll reset lan interface thanks :D

    1 Reply Last reply Reply Quote 0
    • L
      LiquiD_85
      last edited by Jul 20, 2009, 12:31 PM

      I've enabled the "disable webgui anti-lockout rule" and created the follows rule in attachment … but all computer in the lan can access the pfsense's webgui ... it's the LAN -> rule that make it possible for the whole lan or webgui should be disabled anyway?

      thanks LQD

      Rule.jpg
      Rule.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • J
        jahonix
        last edited by Jul 20, 2009, 4:23 PM

        What's your problem with LAN users being shown the login window? They still need user/password to access it.
        But you could create an 'allow' rule for the IP of your admin PC, followed by a modified 'deny' rule in which you set as destination "all BUT gateway-ip". Order of rules is important!

        1 Reply Last reply Reply Quote 0
        • L
          LiquiD_85
          last edited by Jul 22, 2009, 7:20 AM

          I don't want users are trying hours and hourse to guess user/pass. I want my pfsense don't listen at all other ip!
          Why my "disable webgui" don't work now? For 1-2 days i think was working fine!!!

          1 Reply Last reply Reply Quote 0
          • J
            jahonix
            last edited by Jul 22, 2009, 11:59 AM

            @LiquiD_85:

            Why my "disable webgui" don't work now? For 1-2 days i think was working fine!!!

            Sorry, my magic crystal ball is broken.
            Honestly, what kind of help can you expect from "it's broken" without giving any information?

            @jahonix:

            But you could create an 'allow' rule for the IP of your admin PC, followed by a modified 'deny' rule in which you set as destination "all BUT gateway-ip". Order of rules is important!

            1 Reply Last reply Reply Quote 0
            • L
              LiquiD_85
              last edited by Jul 23, 2009, 10:51 AM

              @jahonix:

              Sorry, my magic crystal ball is broken.
              Honestly, what kind of help can you expect from "it's broken" without giving any information?

              Hehehe … very witty :D

              My LAN rule-set is in attachment some post upper ... when i enable in the advanced menù the "disable webgui anti-lockout rule" nothing change anyone can access webgui!!!
              If you need other information ask me!
              If possible i want to use this option and don't create other rules!!!

              Thnx
              LQD!

              1 Reply Last reply Reply Quote 0
              • G
                GruensFroeschli
                last edited by Jul 23, 2009, 10:59 AM

                Umm… Jahonix already posted the solution to why your users still can access the pfSense twice.

                But you could create an 'allow' rule for the IP of your admin PC, followed by a modified 'deny' rule in which you set as destination "all BUT gateway-ip". Order of rules is important!

                Let me rephrase that:
                3 rules:
                allow - source: your_admin_PC, destination: pfSense_LAN_interface
                deny - source: any , destination: pfSense_LAN_interface
                allow - source: any , destination: any

                or easier with only 2 rules:
                allow - source: your_admin_PC, destination: pfSense_LAN_interface
                allow - source: any , destination: **!**pfSense_LAN_interface           (NOT the pfSense_LAN_interface)

                as written: The order of your rules is important !

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • D
                  dramis
                  last edited by Jul 24, 2009, 2:22 PM

                  Simply do in a shell:

                  killall -9 lighttpd

                  1 Reply Last reply Reply Quote 1
                  • C
                    cybrsrfr
                    last edited by Oct 7, 2009, 6:39 AM

                    @dramis:

                    Simply do in a shell:

                    killall -9 lighttpd

                    Is definitely the easy way. In addition to that you could add a package called shellcmd which runs commands when the system starts. Place the killall -9 lighttpd command there and it will kill the GUI when the system starts.

                    1 Reply Last reply Reply Quote 0
                    • 0
                      0tt0
                      last edited by Oct 7, 2009, 9:06 AM

                      Or add another NIC to the system and have users coming in on that interface.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received