• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WEBGUI not responding accessing over wan

Scheduled Pinned Locked Moved webGUI
16 Posts 8 Posters 8.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    Piplfox
    last edited by Oct 15, 2011, 4:21 PM

    Hi I cant access webgui over wan interface. In best scenario I recive an error "The security certificate" and when I click Continue to this website (not recommended) it doesnt get an login page just looping for access andd nothing happens. Over Lan interface everything works fine. ( I am useing pfsense ver 2.0 release). I ve tried to change port number and https/http, restarted webgui from console but nothing hellped. Can anyone help please or any idea what is wrong.

    1 Reply Last reply Reply Quote 0
    • N
      Nachtfalke
      last edited by Oct 15, 2011, 5:12 PM

      Accessing the webGUI over WAN interface you need to open ports in firewaall on WAN tab. By default all ports on WAN are closed.

      Further check under SYSTEM -> ADVANCED for "DNS REBIND CHECK" and "HTTP REFFERER" and change it to your needs.

      1 Reply Last reply Reply Quote 0
      • P
        Piplfox
        last edited by Oct 16, 2011, 8:25 PM

        Off course I ve made NAT port forward and created firewall rules and both of setting you sad are disabled, but the strange thing is that I can reach site of web gui because it ask me to select Continue to this website (not recommended) - website's security certificate and when I select to continue it just reloading indefinitely.

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Oct 17, 2011, 6:21 PM

          You do not need a NAT port forward to reach the GUI from the WAN. Remove it, and it will likely start working.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • P
            Piplfox
            last edited by Oct 18, 2011, 1:14 PM

            Nope this didnt help. Now I dont even recive cert. error page.

            1 Reply Last reply Reply Quote 0
            • P
              podilarius
              last edited by Oct 18, 2011, 2:19 PM

              can you screen shot your rules? please make sure that the NAT for this is removed (port forward or 1:1). If there is any outbound NAT created for this, please remote it also. You will need a rule for HTTP if you are using non-secure web and HTTPS for secured access. If you want to utilize the redirect, you will need both.

              1 Reply Last reply Reply Quote 0
              • C
                cmoegele
                last edited by Oct 19, 2011, 1:03 PM

                I had problems too with standard ports. After reading and trying lots of configurations finally i got it work with
                one TCP rule to Firewall:
                Port 80 does not work to me !?

                ![firewall rule.JPG](/public/imported_attachments/1/firewall rule.JPG)
                ![firewall rule.JPG_thumb](/public/imported_attachments/1/firewall rule.JPG_thumb)

                1 Reply Last reply Reply Quote 0
                • P
                  Piplfox
                  last edited by Oct 19, 2011, 2:52 PM

                  I am useing https and here are rulles:

                  pic1.jpg
                  pic1.jpg_thumb
                  pic2.jpg
                  pic2.jpg_thumb

                  1 Reply Last reply Reply Quote 0
                  • C
                    cmoegele
                    last edited by Oct 21, 2011, 9:40 AM

                    Didn´t get your point does the rules work or do you have problems with this ?

                    1 Reply Last reply Reply Quote 0
                    • P
                      Piplfox
                      last edited by Oct 26, 2011, 10:39 AM

                      I ve still have the problem and rulles working fine on otheri site with other pfsense box.

                      1 Reply Last reply Reply Quote 0
                      • M
                        Metu69salemi
                        last edited by Oct 26, 2011, 10:55 AM

                        try this:

                        1. disable portforward for your pfsense webmin
                        2. create a rule on wan:
                        
                        Action: Pass
                        Disabled: unchecked
                        Interface: WAN
                        Protocol: TCP
                        Source: any (or if you want to determine allowed ip's then you could put it here)
                        Source port: any
                        Destination: your public ip ( or use aliases )
                        Destination port: what is your https/http port
                        Description: firewall management
                        
                        

                        I use aliases: Firewall_mgmt_ips & Firewall_mgmt_ports

                        it just works

                        1 Reply Last reply Reply Quote 0
                        • S
                          ScottNJ
                          last edited by Oct 29, 2011, 12:42 AM

                          Wow, I've never gotten the webgui to work from the wan side for AGES! I had a port forward rule as well as an access rule. The odd things is
                          it works the other way with Monowall, which is what I used to use before moving to pFsense.

                          1 Reply Last reply Reply Quote 0
                          • M
                            Metu69salemi
                            last edited by Oct 29, 2011, 10:52 PM

                            So this is solved?

                            1 Reply Last reply Reply Quote 0
                            • P
                              Piplfox
                              last edited by Nov 3, 2011, 1:17 PM

                              I finaly solved the problem. It wasnt problem with setup on pfsense. The problem was with ADSL line. Internet provider made some changes on their side and now everthing works fine . The problem have been with some https traffic.

                              1 Reply Last reply Reply Quote 0
                              • S
                                ScottNJ
                                last edited by Nov 21, 2011, 2:01 AM

                                @Metu69salemi:

                                So this is solved?

                                No, this for some reason has never worked for me. Hasn't worked on a Dell server, laptop and Soekris box. It starts to open the the Webgui very slowly then it crashes.
                                For whatever reason I never have an issue with Monowall. I assume you configure remote access the same way on both platforms.

                                1 Reply Last reply Reply Quote 0
                                • C
                                  chpalmer
                                  last edited by Nov 21, 2011, 2:26 AM

                                  Piplfox-  13.10.1.0/8 is a routable public address and shouldn't be used on LAN unless your the user of that subnet…  It has the possibility of causing you problems.

                                  http://www.noah.org/wiki/Private_LAN_IP_addresses

                                  Heres a screenshot of the rule on my test box...  I use a nonstandard port on my production boxes...

                                  as pointed out already...  You should have no port forwarding turned on for this rule.

                                  WanRule.JPG
                                  WanRule.JPG_thumb

                                  Triggering snowflakes one by one..
                                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                    [[user:consent.lead]]
                                    [[user:consent.not_received]]