freedomofpress / securedrop-docs

Documentation for the SecureDrop project
https://docs.securedrop.org/
Other
22 stars 26 forks source link

Anti-lockout rule for LAN mentioned in firewall rules warning doesn't exist by default #285

Open huertanix opened 2 years ago

huertanix commented 2 years ago

After completing all previous steps in the firewall setup, after aliases are added, there's a warning at https://docs.securedrop.org/en/stable/network_firewall.html:

Warning Be sure not to delete the Anti-Lockout Rule on the LAN interface. Deleting this rule will lock you out of the pfSense WebGUI.

...but the Anti-lockout rules is not listed in the firewall rules for the LAN interface, so it's warning admins not to delete something that doesn't appear to exist. Adding to the confusion, previous steps of the docs recommend disabling an anti-lockout rule: https://docs.securedrop.org/en/stable/network_firewall.html#disable-anti-lockout-rule which sounds a bit contradicting without a more in-depth understanding of what that checkbox is toggling.

Docs should be updated to remove the warning, since it doesn't seem to apply anymore.

nathandyer commented 2 years ago

I recently followed these steps to set up a pfsense firewall, and am still seeing the anti-lockout rules as originally described. Unless something is unique about the firewall I have, I believe these are still useful to include in the documentation.