<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Safe for external GUI admin login access enabled?]]></title><description><![CDATA[<p dir="auto">I was wondering if it is considered safe to have external  GUI admin access enabled?<br />
If I have a strong password of course. Do others have theirs open to external access?</p>
<p dir="auto">I have it disabled right now, so the only way to access the admin/gui is from inside my network.</p>
<p dir="auto">thanks</p>
]]></description><link>https://forum.netgate.com/topic/54443/safe-for-external-gui-admin-login-access-enabled</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 11:39:51 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/54443.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 Mar 2013 21:54:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Safe for external GUI admin login access enabled? on Sun, 24 Mar 2013 05:06:57 GMT]]></title><description><![CDATA[<p dir="auto">So is it accepted to create a VPN server on the pfsense computer, that you login to first?</p>
]]></description><link>https://forum.netgate.com/post/386176</link><guid isPermaLink="true">https://forum.netgate.com/post/386176</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Sun, 24 Mar 2013 05:06:57 GMT</pubDate></item><item><title><![CDATA[Reply to Safe for external GUI admin login access enabled? on Fri, 22 Mar 2013 14:25:49 GMT]]></title><description><![CDATA[<p dir="auto">I would defenately NOT recommend to allow external access to GUI on WAN.</p>
<p dir="auto">If you can not do as others have suggested before me (VPN etc) and you have to connect externally somehow I would recommend that you at least create an access list and only allow traffic from a small number of known IP addresses. You could combine this with the use of 'denyhosts' or similar techniques to auto block after three failed login attempts or similar.</p>
<p dir="auto">Better safe than sorry. Best is not open anything that you do not really need and to only use secure methods/protocols/configurations, for example if you allow SSH from any to one of your boxes behind the firewall and do not use denyhosts you indirectly allow anybody to gain access to a machine behind the firewall, from this machine they can compromise your entire network (including firewalls) whichs is even worse than "just" allowing anobody to access your GUI on WAN.</p>
]]></description><link>https://forum.netgate.com/post/385947</link><guid isPermaLink="true">https://forum.netgate.com/post/385947</guid><dc:creator><![CDATA[esnakk]]></dc:creator><pubDate>Fri, 22 Mar 2013 14:25:49 GMT</pubDate></item><item><title><![CDATA[Reply to Safe for external GUI admin login access enabled? on Fri, 22 Mar 2013 01:22:34 GMT]]></title><description><![CDATA[<p dir="auto">I VPN into the network or RDP to a LAN machine.  Port is only open via the LAN.</p>
]]></description><link>https://forum.netgate.com/post/385842</link><guid isPermaLink="true">https://forum.netgate.com/post/385842</guid><dc:creator><![CDATA[tim.mcmanus]]></dc:creator><pubDate>Fri, 22 Mar 2013 01:22:34 GMT</pubDate></item><item><title><![CDATA[Reply to Safe for external GUI admin login access enabled? on Thu, 21 Mar 2013 22:34:43 GMT]]></title><description><![CDATA[<p dir="auto">I don't need remote access so I have the custom port I assigned to it blocked by a WAN rule.</p>
]]></description><link>https://forum.netgate.com/post/385818</link><guid isPermaLink="true">https://forum.netgate.com/post/385818</guid><dc:creator><![CDATA[mr_bobo]]></dc:creator><pubDate>Thu, 21 Mar 2013 22:34:43 GMT</pubDate></item></channel></rss>