Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    reset anti-lockout rule

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 988 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wifi75
      last edited by

      hello I have created an aggregation 4 4 LACP network interfaces. the automatically created anti-lockout rule disappeared in the firewall, how can I restore it?

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @wifi75
        last edited by

        @wifi75

        Goto System > Advanced >Admin Access
        and remove the check from :

        ee2180a5-ed01-4475-90b2-949289337bb8-image.png

        Result :

        dc93736b-8c1e-4a6d-932c-a9079265a351-image.png

        I works for a LAN type interface.
        Dono if "aggregation 4 4 LACP" is considered as a "normal" interface.

        The good new : the rule is nothing special - and not essential.
        It's a pass rule for ports 80 and 443, TCP, source : the connected network, for a LAN this is "LAN Address". This rule must be at the top of the rule list.

        It's just a anti shoot in the foot rule, and placed on the LAN interface where only trusted (by the admin) devices are connected.
        All other devices belong on other 'LAN' type interface, and these networks do (should) not have access to the pfSense GUI (the should have a rule that blocks the GUI traffic).

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        W 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          It probably just moved to the new interface when you assigned it. That's expected if you previously only had WAN assigned.

          1 Reply Last reply Reply Quote 0
          • W
            wifi75 @Gertjan
            last edited by

            @gertjan to me it is already like this without the flag

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @wifi75
              last edited by

              @wifi75
              the documentation ** is here : /etc/inc/filter.inc :
              It says :
              /* if antilockout is enabled, LAN exists and has
              * an IP and subnet mask assigned
              */
              for systems with more then 1 interface, and one interface is known as the 'lan'.
              Or, systems with 1 interface, and that interface is known as the 'wan'.

              I guess your "LACP" isn't isn't qualified as the 'lan'.

              Don't bother : create the rule yourself on the interface you like.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by stephenw10

                Looks like you may be running a very old version: https://forum.netgate.com/post/1020459
                Unless that's not your screenshot.

                Not that it should make any difference to this.

                W 1 Reply Last reply Reply Quote 0
                • W
                  wifi75 @stephenw10
                  last edited by

                  @stephenw10 linke this it is ok?
                  f9baaa17-97f0-47f5-9337-b48a3525a935-image.png

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    That looks fine for general access.

                    You don't really need those top two rules, the pass-all rule covers that traffic.

                    The anti-lockout rule will be on your VLAN10 interface.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.