OPNsense Forum

Archive => 16.7 Legacy Series => Topic started by: bringha on December 16, 2016, 05:10:28 pm

Title: HELP: Did lock me out from opnsense
Post by: bringha on December 16, 2016, 05:10:28 pm
Hi there,

I am in big trouble as i have locked me out from opnsense completely:

I accidentially disabled the lan port in GUI and I do not get the console up an running (no login). What options do I have now to get access to the system and patch the setting for the LAN again? Where is this config stored?

Looking forward to your reply!

With despreate greetings

Br
Title: Re: HELP: Did lock me out from opnsense
Post by: franco on December 16, 2016, 05:16:54 pm
Config is under /conf/config.xml and the backups under /conf/backup/ -- moving the latest good backup over /conf/config.xml and rebooting should fix it.

Worst case you can use an image (cdrom/vga/serial) and boot into live mode (exit installer if it auto-started or chose the live cd at the prompt), mount from there and fix.

PS: SSH+root console has a config restore feature, item "13".
Title: Re: HELP: Did lock me out from opnsense
Post by: bringha on December 16, 2016, 06:11:17 pm
Hi Franco

Thanks for your reply!!!!!

I made an USB absed image and tried to boot! Unfortumately it hangs at the same place as when booting from disk. The last message  I see is

Ums0: <vendor 0x557 product 0x2419 class 0/0 rev 1.10 ...> on usbus0
Ums0: 3 buttons and 2 corrdinates ID = 0

Is this an APCI problem?

BR C
Title: Re: HELP: Did lock me out from opnsense
Post by: franco on December 16, 2016, 08:35:36 pm
Hm, what kind of image did you use and do you have a monitor attached or serial cable?
Title: Re: HELP: Did lock me out from opnsense
Post by: bringha on December 18, 2016, 01:25:34 pm
Hello together,

after a long night I managed to get my opnsense firewall back to access.Here what the problem was and what I did:


I finally managed to boot a vanilla FreeBSD installer and could open a shell, mount the OPNsense disk and reinstalled the old config. Everything is fine now again.

It is a while ago that I accessed the Opnsense via console (normally I use ssh remotely) but something must have changed obviously in the loader step 3 (?).

When I activated the maximum detailed boot log outputs, I could see that the last output was the aforementioned 'now try to run /sbin/init' (or so) which is if I remember correctly when entering stage 3 of the boot process in Freebsd. No clue why the Output over serial console then stops ...

If I may express a wish then it would look like:

Anyhow, will send an update when having done the analysis. @Franco: Once again a big thank you for the fast responses ...

Br br
Title: Re: HELP: Did lock me out from opnsense
Post by: abel408 on July 19, 2017, 04:24:01 am
Hey bringha... Sorry to bring up an old thread, but did you ever get your login prompt back? My opnsense is stuck after mounting the opnsense disk and then just displays my USB devices. Only thing I can do is scroll lock and page up and down the boot output. I also believe I locked my self out some how by enabling ids. I also have a supermicro board. I wonder if I can access the console from ipmi...
Title: Re: HELP: Did lock me out from opnsense
Post by: abel408 on July 20, 2017, 02:20:36 am
Thanks Franco for your help. I was able to revive my system by using a FreeBSD live cd and mounting my gmirror. The I edited the /conf/config.xml file to NOT include the lan interface on IDS. After that and a reboot, OPNSense started up and I was able to ssh and log into the web interface once again.

I also fixed my console by going to System -> Settings -> Administration and changing the primary console from Serial to VGA. Not sure why it was set to Serial. I'm guessing an OPNSense update changed it as I wasn't having any console issues when it was first installed.