Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Locked myself out, need help to get back in

Hello all,

I did something incredibly stupid, i activated a erroneous NAT rul and i locked myself out.
Is there anyway i can undo this form the console?

Any help would be greatly appreciated. 



This thread was automatically locked due to age.
  • So i managed to restore the FW. Turned out that it wasn't all that difficult after all.

    Connected a screen and a keyboard to the FW machine, rebooted to the previous firmware version (SFOS 18.5.2 MR-1).
    This also reverted the configuration to the status of the FW before the latest upgrade.
    Logged in to the web admin page and re-applied the upgrade to SFOS 18.5.2 MR-2.

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • Thank you for your suggestion, just registered and added my FW tot Sophos Central.

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • Did you try to enter the above command and access the Admin Portal (Web GUI) to disable the NAT rule?

  • Hi Marek,
    Thank you, but as far as i can see it doesn't solve my problem. I need to disable a NAT rule to re-enable contacting the management web site.

    If nothing seems to work i see no other option than trying resetting through the CLI and then restoring from a recent backup.

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • console> system appliance_access show|enable|disable

    It should help. For more information visit: https://support.sophos.com/support/s/article/KB-000038694

  • Thank you.
    Thinking about it, i have a recent backup.
    Can i restore this from CLI?

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • Home can also integrate to Central without any problems. Central is for free in a base version (Simply start a trial and let all licenses expire, Wireless and FW Management will still stay). This would help in such situations. 

    But to get access to the firewall, you would have to manipulate the database to get this NAT rule out of play. Let me think about this. 

    __________________________________________________________________________________________________________________

  • Hello Tony, no I am a home user 

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • Do you have Central activated? Central should be still possible. 

    __________________________________________________________________________________________________________________

  • Hi Wayne, thats exactly what i'm looking for.
    Thank you for clarifying that.

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]