Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking access to ntop

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Boguslaw
      last edited by

      How to block access to LAN users 192.168.1.0 (except 192.168.1.11)  to ntop 192.168.1.1:3000. For example: I can use ntop but other users can't. How to do it?

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        block, tcp, source NOT <allowed client's="" ip="">, destination <lan ip="" of="" pfsense="">, port <ntop port="">, gateway default</ntop></lan></allowed>

        1 Reply Last reply Reply Quote 0
        • B
          Boguslaw
          last edited by

          My settings:
          But it doesnt work. Everybody has access to ntop

          3.JPG
          3.JPG_thumb
          3.JPG_thumb

          1 Reply Last reply Reply Quote 0
          • S
            sullrich
            last edited by

            @Boguslaw:

            My settings:
            But it doesnt work. Everybody has access to ntop

            From a shell issue this command:

            cat /tmp/rules.debug |grep 3000

            And post the results.  Thanks!

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              You have to disable the antilogout rule at lan (system>advanced) which grants access to the lan IP of the pfsense. This rule is in place to make sure you don't log yourself out from the administration. Beware that disabling that rule might log you out if you have incorrect rules at LAN, so verify your settings before applying a new ruleset.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.