SG1100 - Can´t login webGUI sometimes after 21.05.1 upgrade.
-
Hello guys.
After the 21.05.1 upgrade sometimes i can´t login to webGUI, since we disable our SSH (due to attacks and by recommendation by our SOC) what can i do?
Our SG1100 doesn´t have a VGA port.
In my opinion after the 2.5 upgrades our problems starts here.
We have seven SG1100 in production, CPU is allways at 100% too in the web GUI.
I´m really worried about this. -
Hard to speculate about what might be happening with that little information to go on.
You can setup access using the serial console to check the state of the system when you cannot reach it.
If it's over time, it may be a memory leak like the known issue with
pcscd
, which has come up several times recently. https://redmine.pfsense.org/issues/11933#note-7You can install the System Patches package and then create an entry for
afcc0e9c97c1993ae6b95f886665fcb4375d26c7
to apply the fix.Then reboot once after.
Even if that isn't 100% the cause it's good to eliminate the possibility.
Beyond that you'll need to setup serial console access and when it's in the broken state, drop to the shell and check the logs, running processes, etc, and see if anything stands out.
SSH isn't inherently bad, you just need to restrict access to approved management network(s) or host(s). It should never be exposed to the Internet or other public networks (and neither should the GUI), but locally and privately it's a benefit, not a liability.
-
@adrianoebm said in SG1100 - Can´t login webGUI sometimes after 21.05.1 upgrade.:
CPU is always at 100% too in the web GUI
Did you follow the suggestions in your thread about that?