Forum Discussion
Ali_F_101979
Nimbostratus
Jan 29, 2008Restrict admin GUI to certain IPs
Using 3400 & 6400 with v9.4.3 HF1, I used the following commands to restrict GUI (webadmin) access to one ip: (example)
b httpd allow 192.168.1.254/255.255.255.255
b save all
bigstart restart httpd
The above doesn't work. If I look at /etc/hosts.allow file, I don't see the above restriction being added! I didn't try to modify /config/httpd.conf and /etc/hosts.allow files manually because at the top of the files, they say:
THIS IS AN AUTO-GENERATED FILE -- DO NOT EDIT!!!
Use the bigpipe shell utility to make changes to the system configuration.
Does anyone know how to restrict management https access to one or more IP addresses?
Thanks!
- hoolio
Cirrostratus
When you change use b httpd allow IP, it should modify the internal database and the httpd.conf. You can view the configuration using 'b db list'. The key is called service.httpd.allow: - Ali_F_101979
Nimbostratus
Thanks Aaron. I just tested again and noticed that if I add "deny from all" to httpd.conf, it will work. A workaround is to copy modified httpd.conf and restart daemon in "/config/startup" file everytime F5 starts up. But, i will check with tech support for a permanent fix.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects