• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Disable WAN interface Web UI

Scheduled Pinned Locked Moved webGUI
4 Posts 3 Posters 953 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    praveen02
    last edited by Oct 13, 2021, 5:22 PM

    The Pfsense WAN interface is accessible over 443. How Can we disable this access to Web UI of the pfsense from WAN public IP

    V 1 Reply Last reply Oct 13, 2021, 5:33 PM Reply Quote 0
    • V
      viragomann @praveen02
      last edited by Oct 13, 2021, 5:33 PM

      @praveen02
      pfSense does not allow access on WAN as long as you do not add a firewall rule manually allowing it.

      J 1 Reply Last reply Oct 13, 2021, 7:05 PM Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator @viragomann
        last edited by Oct 13, 2021, 7:05 PM

        @viragomann my guess is he is accessing via the lan side..

        Which yeah with the any any rule on lan this would be accessible.

        If you do not want the gui to be accessible via a lan side network, you would need to block it specifically. Pointless on the lan if the anti lock out rule is in place. But on other interfaces. A good alias to use is the built in "this firewall" this can be used to block access to any IP of pfsense, even if they change - like say a wan IP..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        V 1 Reply Last reply Oct 13, 2021, 7:42 PM Reply Quote 0
        • V
          viragomann @johnpoz
          last edited by Oct 13, 2021, 7:42 PM

          @johnpoz
          Yeah, that's an option of course. I was thinking of this and reread the part "from WAN public IP" twice and toke it as "from WAN interface".

          Also not sure if he added a rule for allowing TCP 443 to WAN to forward it to a server behind. In this case it would be a good advice to change the web configurators port to any other.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received