Is the Web GUI bound to your WAN interface? Have you enabled HAProxy or some other plugin that might use those ports?
Quote from: ChrisH on November 10, 2017, 10:00:59 amIs the Web GUI bound to your WAN interface? Have you enabled HAProxy or some other plugin that might use those ports?I have not changed another options except port fording. where could I check those options which you said?
Might be because of the default, non-editable and non-lower-placeable rule "Anti-lockout rule"?... I never tried to port-forward 80 and/ or 443, didn't need it, but it would make sense that, as long as you don't disable the Anti-lockout Rule, which by default is enabled and works on 80 and 443, to not be able to access any other IP addr., than of the OPNsense itself?!?!
ddqlooYou should change the port for the webgui if you intend to forward port 443.A good description of portforwarding port 80 and 443 can be found in this topic:https://forum.opnsense.org/index.php?topic=6356.0@ChrisH: The web gui can be accessed via any interface of the OPNsense, provided firewall rules allow you in. That is why you want to change the port for the web gui. If you don't do that, WAN port 443 will be in use for the web gui.@hutiucip: The anti-lockout rule is just there to prevent you accidentally lock yourself out of the web gui by blocking the port that the web gui listens on. That is why the anti lockout rule always allows the port for the web gui from the LAN interface.Kind regards,Bert