Recommended Posts

I know that I'm not the greatest at this stuff. Normally I'm impressed with pfsense, but I've got an issue that I can't quite figure out. Right now, for some reason, I can access the webgui for my pfsense box from my WAN port, something that I do not want since my WAN port is exposed to the internet. I changed the default webgui part to 88, and created a rule to block all WAN traffic to port 88 but still I can access it by typing in the wan ip address and port into the web browser. Here's a screenshot of the firewall rules. The first rule should allow ssh traffic from the WAN port (internet) to a specific device on my network. The second rule should block any WAN traffic to port 88. The first rule works properly, the second does not. I think that there's a conflict somewhere... any ideas? Thanks.

post-5498-0-63048900-1361905924.jpg

Link to comment
https://www.neowin.net/forum/topic/1138726-pfsense-disable-webgui-on-wan/
Share on other sites

the web gui would not be open to the public wan IP.. You should not need a specific rule! By default ALL unsolicited traffic to wan is blocked by default.

You sure your accessing it via wan and not the lan?

How do you have your pfsense setup in your network.. Is the wan on the public NET!! or is it behind a nat already? On a work call currently, but as soon as finishes will take a look at the pfsense config to allow it to happen.

Also what version are you running? 2.0.2, 2.1? 2.0.3 ?

I just checked mine and its not open to public - are you accessing it via a nat reflection or something. Since you have changed the port, have you check the Disable webConfigurator redirect rule option the advanced settings.

post-14624-0-48686900-1361910054.png

What I think could be happening is you have the antilockout rule running on your lan. and then hitting it maybe via nat reflection?

BTW: Such a question is better suited for the pfsense forums, very responsive people there! Me being one of them ;) Just use a different nick there.

You are correct, it was NAT reflection that was allowing me to access the webgui; canyouseeme shows the port as closed.

However, now I have another problem. I have a NAT rule to forward traffic on port 22 to a local IP address, and it automatically created the needed firewall rule as you can see in the screenshot on the original post, but canyouseeme shows port 22 as closed. Here's the NAT redirect rule:

If WAN TCP

SRC addr = *

SRC ports = *

DEST addr = WAN address

DEST ports = 22

NAT IP = (IP address of device I want external access to)

NAT ports = 22

I have deleted the firewall rule to block traffic on port 88, but have left the rule to allow traffic on port 22

the pfsense box WAN port is connected to internet, no other NAT device on the network.

I'm running pfsense 2.0.2

glad you got it all sorted.. I don't have nat reflection even enabled - I personally have no use for it, nor do I really understand any use for such a thing.. Why would you bounce off your routers wan IP just to be directed back to a local box.. Just hit the local box directly - setup your name resolution accordingly, etc.

This topic is now closed to further replies.
  • Posts

    • Windows Server gets DNS over HTTPS (DoH) support by Usama Jawad For the past few months, Microsoft has been previewing DNS over HTTPS (DoH) for Windows DNS Server, touting it as a foundational upgrade for zero-trust enterprise networks. It essentially introduces encrypted, authenticated DNS for the networks rather than transmitting DNS traffic in clear. Now, the company has introduced the general availability (GA) of this feature. The GA of DoH encourages organizations to deploy the solution in production environments without implementing a new client-to-resolver architecture. DoH helps improve the overall security of the network and reduces the risk of spoofing due to its zero-trust design. This is a significant change because pretty much every interaction with the network requires interfacing with DNS. DoH offers several advantages over standard DNS traffic, such as encryption using HTTPS, preventing unauthorized inspection, man-in-the-middle attacks, and traffic analysis. Since it leverages TLS certificates so that clients can verify the identity of the DNS server, it prevents spoofing through this authentication mechanism. Additionally, it's built on the DoH standard defined by the Internet Engineering Task Force (IETF), which means that it should work with modern RFC 8484-compliant clients. Finally, it integrates into the existing network architecture seamlessly and can even run in parallel with standard DNS, so that customers can migrate to the new technology at their own pace. Microsoft says that in the past few months of preview, DoH has become more stable, and customers can confidently deploy it in production environments with proper guidance. Microsoft has emphasized that migrating to DoH is necessary for organizations that are moving toward zero-trust DNS solutions. Windows clients already support DoH, but the latest availability on Windows Server provides encrypted DNS to all endpoints. The company has also mentioned that "while this release focuses on encrypting client-to-resolver communication, support for encrypted communication between Windows DNS Server and upstream DNS resolvers is planned for a future update." You can follow Microsoft's guidance to deploy DoH here, but keep in mind that you need a Windows Server 2025 installation with the latest Patch Tuesday updates installed.
    • Lol I had one of these turn faulty in Jan, guess it wasn't just bad luck lol
    • I'm team Rossmann all the way. I have the exact same NVME, altough not in an array like him.
    • It had gone weeks ago. Although thinking about it I'm on the beta.
    • They thought value of their goods would forever only drop like it used to and didn't account for sudden increase in price because of all the Ai hype. Tough luck Samsung, don't try to weasel this one out. Also American customer protection laws are a**. In Europe, you need to be compensated for a functioning product of same or better characteristics (not same price point as when it was originally bought!) if it can't be repaired and when you receive a replacement product your warranty starts from scratch because you received a different item than you previously had and old warranty thus cannot apply to it anymore. If your actual item was successfully repaired, warranty gets extended for the period the item was in service. If item is repaired to a significant extent, warranty also starts over from scratch because major part of it was replaced. Americans need to fight to get this kind of consumer protections because they are constantly getting screwed over.
  • Recent Achievements

    • Week One Done
      davidbazooked earned a badge
      Week One Done
    • One Month Later
      Jamswaz earned a badge
      One Month Later
    • Week One Done
      Jamswaz earned a badge
      Week One Done
    • Rookie
      Marzoid went up a rank
      Rookie
    • Community Regular
      coch went up a rank
      Community Regular
  • Popular Contributors

    1. 1
      +primortal
      511
    2. 2
      PsYcHoKiLLa
      184
    3. 3
      +Edouard
      159
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      75
  • Tell a friend

    Love Neowin? Tell a friend!