securedrop-docs icon indicating copy to clipboard operation
securedrop-docs copied to clipboard

Anti-lockout rule for LAN mentioned in firewall rules warning doesn't exist by default

Open huertanix opened this issue 2 years ago • 1 comments

After completing all previous steps in the firewall setup, after aliases are added, there's a warning at https://docs.securedrop.org/en/stable/network_firewall.html:

Warning Be sure not to delete the Anti-Lockout Rule on the LAN interface. Deleting this rule will lock you out of the pfSense WebGUI.

...but the Anti-lockout rules is not listed in the firewall rules for the LAN interface, so it's warning admins not to delete something that doesn't appear to exist. Adding to the confusion, previous steps of the docs recommend disabling an anti-lockout rule: https://docs.securedrop.org/en/stable/network_firewall.html#disable-anti-lockout-rule which sounds a bit contradicting without a more in-depth understanding of what that checkbox is toggling.

Docs should be updated to remove the warning, since it doesn't seem to apply anymore.

huertanix avatar Nov 30 '21 01:11 huertanix