WebGUI access from WAN??

Started by norspang, June 04, 2015, 10:04:23 AM

Previous topic - Next topic
If I need access to a WAN Port I change the port of the management and open the Port from my fixed IP to the WAN Interface. The rule belongs on WAN Interface. That's it.

Never open it for the complete Internet.
Twitter: banym
Mastodon: banym@bsd.network
Blog: https://www.banym.de

When WebGUI access from WAN, if source is private IP, remember to uncheck "Block private networks" in Interface setting.

Quote from: jwright on March 15, 2020, 10:42:53 PM
Try disabling reply-to on WAN rules (Firewall > Settings > Advanced)

I was looking for a solution to a similar problem for a long time.
This solved my problem !
thank you very much

Quote from: jwright on March 15, 2020, 10:42:53 PM
Try disabling reply-to on WAN rules (Firewall > Settings > Advanced)

This one is working for me.

March 04, 2024, 10:24:58 PM #19 Last Edit: March 04, 2024, 10:26:55 PM by chrcoluk
I think OPNsense could do with an option on the console for punching an initial hole through to the UI for a specific WAN IP, I think a rule that specifically whitelists an IP is fine.  The default LAN only assumes one is running the firewall local to them so they can just access over a LAN, but this falls apart on remote installations, and adding a firewall rule in the console, when the whole software is designed to be managed from the UI is clearly not a clean way of doing it, hopefully a solution can be found.

As it stands now it is pfctl -d disable the entire firewall, then going into the UI to add some kind of management IP ACL rule for access the UI and finally turning the firewall back on with apply.
OPNsense 24.1

I've never liked the idea of allowing access to the OPNSense WebUI from the Internet.  I set up Wireguard on OPNsense and if I need to log into my OPNsense system when away from home, I just fire up the Wireguard VPN on whatever device I'm using.

Well your case is a local install, if OPNsense is remote you need to at the very least have some kind of initial WAN access.  Even if its to setup a VPN.
OPNsense 24.1