Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Assigning gui to other vlan for security

    Scheduled Pinned Locked Moved webGUI
    3 Posts 3 Posters 156 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jgatzek
      last edited by

      Ok, this may sound a bit picky, but I don’t want any interface to have access to the web gui except on my management vlan only. The dhcp and firewall live on the lan port and I want that locked down and it is my trunk to the switch. Traffic is allows to only use the services available thru the lan port.

      The gui, console, or any other configuration tools must not be allowed any access from any port except the management vlan.

      When changing if it via assigning ip address to interface via console, my network acts funny and at times I lost access to gui. How do I define which vlan has gui access in the gui to complete my configuration?

      M luckman212L 2 Replies Last reply Reply Quote 0
      • M Offline
        marcg @jgatzek
        last edited by marcg

        @jgatzek Add a block rule on all interfaces except the one(s) where you want management access. Don't block access to other TCP/UDP ports on the firewall needed for DHCP, DNS, etc.

        a0ab488c-815b-4058-b345-04150169d256-image.png

        1 Reply Last reply Reply Quote 1
        • luckman212L Online
          luckman212 LAYER 8 @jgatzek
          last edited by

          Just adding one quick tip: if you ever lock yourself out of the GUI by mistake, drop in to the console, choose option 8 and then run pfctl -d to temporarily disable the firewall.

          You should be then able to access the GUI and fix the issue. If you make changes and save/apply, the firewall will be re-enabled, so if you haven't fixed it then you'll get locked out again (rinse & repeat if needed)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
          Privacy Policy · Cookie Policy