Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Changed both SSH and HTTP ports (and forgot to adjust my rules)...

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 2 Posters 639 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      furom
      last edited by

      Hi,
      subject says it all more or less.. I'm locked out - but do have a fresh backup thankfully.

      So question is what are my options? Do I need to flash an image through console or is there a better way?

      Thanks

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @furom
        last edited by johnpoz

        @furom Had you turned off the antilock out rule? Can you not connect via the lan network, this is the network that has the antilock out rule and this rule would be updated when you changed your ports.

        lockout.jpg

        If you have console access you should be able to just roll back your config, or worse case scenario just turn off all firewall rules to allow you access temp to change the rules to allow your access, etc.

        pastconfigs.jpg

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        F 1 Reply Last reply Reply Quote 0
        • jimpJ jimp moved this topic from Problems Installing or Upgrading pfSense Software on
        • F
          furom @johnpoz
          last edited by

          @johnpoz said in Changed both SSH and HTTP ports (and forgot to adjust my rules)...:

          @furom Had you turned off the antilock out rule? Can you not connect via the lan network, this is the network that has the antilock out rule and this rule would be updated when you changed your ports.

          lockout.jpg

          If you have console access you should be able to just roll back your config, or worse case scenario just turn off all firewall rules to allow you access temp to change the rules to allow your access, etc.

          Hi,
          No, the anti-lockout rule should be intact, in fact, I was relying on that catching my stupidity if I messed this up, but I could not connect still. I need to check that when back in... I can get console access though, just have to read up on how to connect - I have done it once... :) Thanks for the tip and pics!

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @furom
            last edited by

            @furom this could be handy as well

            https://docs.netgate.com/pfsense/en/latest/troubleshooting/locked-out.html#troubleshooting-access-when-locked-out-of-the-firewall

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            F 1 Reply Last reply Reply Quote 1
            • F
              furom @johnpoz
              last edited by

              @johnpoz said in Changed both SSH and HTTP ports (and forgot to adjust my rules)...:

              @furom this could be handy as well

              https://docs.netgate.com/pfsense/en/latest/troubleshooting/locked-out.html#troubleshooting-access-when-locked-out-of-the-firewall

              That was really nice of you, spot on! Thank you!!

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @furom
                last edited by

                @furom no problem - also don't forget, try your old ports - maybe your port changes didn't actually apply like you thought they did ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                F 2 Replies Last reply Reply Quote 0
                • F
                  furom @johnpoz
                  last edited by furom

                  @johnpoz Probably a silly thing, but when connecting I get nothing, but am connecting @115200/8/N/1... Do I need to restart the Netgate?

                  Edit: Changed console util and got in... :)

                  1 Reply Last reply Reply Quote 0
                  • F
                    furom @johnpoz
                    last edited by

                    @johnpoz said in Changed both SSH and HTTP ports (and forgot to adjust my rules)...:

                    @furom no problem - also don't forget, try your old ports - maybe your port changes didn't actually apply like you thought they did ;)

                    Great advice, but unfortunately they did... :)

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @furom
                      last edited by

                      @furom so was the antilockout disabled? Were you coming in on a different interface then where the antilock is? When you changed the port this should of changed for sure...

                      Example.. See my previous post, I just changed my ssh port and there you go it changed..

                      connect.jpg

                      And can connect on that port.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      F 1 Reply Last reply Reply Quote 1
                      • F
                        furom @johnpoz
                        last edited by

                        @johnpoz said in Changed both SSH and HTTP ports (and forgot to adjust my rules)...:

                        @furom so was the antilockout disabled? Were you coming in on a different interface then where the antilock is?

                        Exactly it. I was connecting through another interface. I wish I had remembered that, but thankfully not that often I need it... :)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.