Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Change the LAN firewalling

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 4 Posters 4.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? This user is from outside of this forum
      Guest
      last edited by

      If you've disabled the web gui anti-lockout rule for LAN,

      But how could i disable it since right now, i can't access to the web interface ?

      the rule disable all traffics in the LAN…

      1 Reply Last reply Reply Quote 0
      • ? This user is from outside of this forum
        Guest
        last edited by

        Blocked access with firewall rules

        If you blocked yourself out of the WebGUI remotely with a firewall rule, there may still be hope. This shouldn't happen from the LAN as there should be an anti-lockout rule that maintains access to the WebGUI from that interface.

        Having to walk someone on-site through fixing the rule is better than losing everything!

        Well, i can't access from the LAN…

        Is is possible to disable the rule for the LAN interface by the console ?

        Thank you in advance.

        ++

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG Offline
          GruensFroeschli
          last edited by

          @Efonne:

          If you've disabled the web gui anti-lockout rule for LAN, I think you can re-enable it by setting the LAN IP address from the console.

          ↑

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • ? This user is from outside of this forum
            Guest
            last edited by

            If you've disabled the web gui anti-lockout rule for LAN, I think you can re-enable it by setting the LAN IP address from the console.

            ??? Well i don't really understand… ???

            I did not disable "the web gui anti-lockout rule for LAN".
            I did make a rule on the firewall configuration that disable all traffics from the LAN.

            I've tried to set the LAN IP address with the console but i still can not access.

            I did disable the firewall :

            pfctl -d
            

            But i still can't access to the webgui.

            With which command could i modify the /tmp/rules.debug file, please ?
            I tried emacs, vim, nano but these commands do not existe.

            ++

            1 Reply Last reply Reply Quote 0
            • ? This user is from outside of this forum
              Guest
              last edited by

              I found "ee" command to edit a file.

              1 Reply Last reply Reply Quote 0
              • ? This user is from outside of this forum
                Guest
                last edited by

                Well i can now edit /tmp/rules.debug but i can not find my "rule" that block all the LAN traffics…

                I'm still blocked...

                1 Reply Last reply Reply Quote 0
                • K Offline
                  kpa
                  last edited by

                  You don't have to edit anything, just do what Efonne told you, reset the LAN address using option 2) in the console menu.

                  1 Reply Last reply Reply Quote 0
                  • E Offline
                    Efonnes
                    last edited by

                    If you want to do it by manually editing /tmp/rules.debug anyway, run pfctl -o basic -f /tmp/rules.debug after you are done to reload the rules.

                    1 Reply Last reply Reply Quote 0
                    • ? This user is from outside of this forum
                      Guest
                      last edited by

                      @kpa:

                      You don't have to edit anything, just do what Efonne told you, reset the LAN address using option 2) in the console menu.

                      Just said, i did this action several time.
                      And i connected to the LAN interface directly to access but i did not success…

                      1 Reply Last reply Reply Quote 0
                      • ? This user is from outside of this forum
                        Guest
                        last edited by

                        Well, my apologies.
                        It seems that's re-enable the set up of the LAN does resolve the problem.

                        I had some ethernet cable trouble…

                        Thanks again for your help.
                        ++

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.