Project

General

Profile

Actions

Bug #9342

closed

SSH To Public IP Of pfSense Router Bricks Firewall Until Restart On XG-7100

Added by Alex Trottier about 5 years ago. Updated about 5 years ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/20/2019
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:

Description

Coreboot version: ADI_PLCC-01.00.00.10
pfSense version: 2.4.4-RELEASE-p2

Issue:

While doing some pen-testing of our firewall, I discovered an alarming issue in which a simple `ssh <public-ip-of-firewall>` was enough to completely brick the firewall, shutting off all internet access, and access to services that sit behind the firewall. So far the only way I can get around the issue is to hard restart the firewall. After coming online again, `ssh <public-ip-of-firewall>` will bring down the firewall again.

I have a few public facing services on the firewall including:
1) HAProxy
2) Suricata

I have checked system logs, package logs, etc... and haven't been able to find anything alarming or out of the ordinary.

Actions

Also available in: Atom PDF