Actions
Bug #9342
closed
AT
SSH To Public IP Of pfSense Router Bricks Firewall Until Restart On XG-7100
Bug #9342:
SSH To Public IP Of pfSense Router Bricks Firewall Until Restart On XG-7100
Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/20/2019
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
Description
Coreboot version: ADI_PLCC-01.00.00.10
pfSense version: 2.4.4-RELEASE-p2
Issue:
While doing some pen-testing of our firewall, I discovered an alarming issue in which a simple `ssh <public-ip-of-firewall>` was enough to completely brick the firewall, shutting off all internet access, and access to services that sit behind the firewall. So far the only way I can get around the issue is to hard restart the firewall. After coming online again, `ssh <public-ip-of-firewall>` will bring down the firewall again.
I have a few public facing services on the firewall including:
1) HAProxy
2) Suricata
I have checked system logs, package logs, etc... and haven't been able to find anything alarming or out of the ordinary.
Actions