OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Disabling OPNsense web GUI and configd daemons
« previous next »
  • Print
Pages: [1]

Author Topic: Disabling OPNsense web GUI and configd daemons  (Read 2844 times)

FrenchFries

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Disabling OPNsense web GUI and configd daemons
« on: May 26, 2019, 03:53:44 pm »
Hello,

I am currently using OpenBSD as a firewall, as the attack surface is really small. I am considering moving to OPNsense ...

After configuring OPNsense, I would like to disable the web interface and config daemons from SSH console (preferably using the text prompt). When I need to modify the configuration, I only need to logon the serial/ssh console and enable web GUI and configd again. How can I do that ?

On modern switches with a UI, you only use the UI during configuration, then you disable it.

Does it sound like a reasonable feature to add on the To-do list?

Kind regards,
French Fries
« Last Edit: May 26, 2019, 04:00:01 pm by FrenchFries »
Logged

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Disabling OPNsense web GUI and configd daemons
« Reply #1 on: May 26, 2019, 04:10:45 pm »
Quote from: FrenchFries on May 26, 2019, 03:53:44 pm
After configuring OPNsense, I would like to disable the web interface and config daemons from SSH console (preferably using the text prompt). When I need to modify the configuration, I only need to logon the serial/ssh console and enable web GUI and configd again. How can I do that ?

You can in theory kill the daemons but you may get a broken system since cron is using configd calls too. The web interface should not be a problem (can be restarted by the console menu if needed but still a bad idea since the HTTP based configuration is the main configuration utility in contrast to the systems with SSH / console as main access module). You can for example disable SSH as an alternative if you want only one open port.

Quote from: FrenchFries on May 26, 2019, 03:53:44 pm
On modern switches with a UI, you only use the UI during configuration, then you disable it.
The UI is still not the main configuration utility of them - that's still RS232 / USB or SSH/Telnet

Quote from: FrenchFries on May 26, 2019, 03:53:44 pm
Does it sound like a reasonable feature to add on the To-do list?
No
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: Disabling OPNsense web GUI and configd daemons
« Reply #2 on: May 26, 2019, 07:48:46 pm »
You can bind web gui just to lan or even better - dedicated management interface and restrict web access to your ip.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Disabling OPNsense web GUI and configd daemons
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2