Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disbable webConfigurator on one interface

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    2 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Slab
      last edited by

      Is is possible to disable access to the webConfigurator on any given interface? For example, I've just configured a DMZ subnet on a new ethernet adapter, blocked access to the LAN subnet from the DMZ, and enabled access to the WAN from the DMZ. Everything works as expected, but I've discovered that clients in the DMZ can point their web browser at the default gateway for the interface and get to the webConfigurator …I would prefer not to have that happen. I just want to allow webConfigurator access from the LAN subnet. I didn't see a means to accomplish this via the gui ...perhaps I've missed it. Thx...

      1 Reply Last reply Reply Quote 0
      • W
        wallabybob
        last edited by

        Try a firewall rule on the DMZ interface blocking (with logging) anything from DMZ subnet to DMZ address port 80 (http). Add a rule on the DMZ interface blocking (with logging) anything from DMZ subnet to DMZ address port 443 (https). Reset firewall states (Diagnostics -> States, click on Reset States tab, click on Reset button). Test, check the access attempts are logged in the firewall log (Diagnostics -> System Logs, click on Firewall tab) and then (if desired) go back and edit these rules to disable logging.

        Adjust rules appropriately if you have chosen to configure a custom port number for access to web configurator.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.