Assigning gui to other vlan for security
-
Ok, this may sound a bit picky, but I don’t want any interface to have access to the web gui except on my management vlan only. The dhcp and firewall live on the lan port and I want that locked down and it is my trunk to the switch. Traffic is allows to only use the services available thru the lan port.
The gui, console, or any other configuration tools must not be allowed any access from any port except the management vlan.
When changing if it via assigning ip address to interface via console, my network acts funny and at times I lost access to gui. How do I define which vlan has gui access in the gui to complete my configuration?
-
@jgatzek Add a block rule on all interfaces except the one(s) where you want management access. Don't block access to other TCP/UDP ports on the firewall needed for DHCP, DNS, etc.

-
Just adding one quick tip: if you ever lock yourself out of the GUI by mistake, drop in to the console, choose option
8and then runpfctl -dto temporarily disable the firewall.You should be then able to access the GUI and fix the issue. If you make changes and save/apply, the firewall will be re-enabled, so if you haven't fixed it then you'll get locked out again (rinse & repeat if needed)
Privacy Policy · Cookie Policy