1
23.1 Legacy Series / Re: Upgraded from 22 to 23.1 - Web Gui now inaccessible
« on: May 19, 2023, 07:00:48 pm »https://docs.opnsense.org/manual/settingsmenu.html#listen-interfaces
Hi Franco. I looked at the setting, and the wording of the warning doesn't convey the message you think it does.
The warning says you should know what you're doing if you want to only listen on certain interfaces. I work with multiple NGFW vendors for my job. I know what I'm doing, and it's a best practice to not listen for management traffic on WAN, DMZ, or other untrusted interfaces. If following that best practice is dangerous on OpnSense, the warning needs to say something like "selecting interfaces here may make the GUI inaccessible if the interface is unavailable when the web GUI starts. Use with caution."
I appreciate you guys developing the product and making it publicly available. Making warning messages less dependent on tribal knowledge will be helpful to people who are new to the product. Also, identifying why the settings were ok on the previous version, but not ok on this version might unearth a bug or provide an opportunity to make the product more robust.
In the meantime, I will remove the interface list setting and try to use policy to block management access on external/untrusted interfaces.
Cheers