Note: For an improved how to, please see our companion article Restrict Pfsense 2.4.x Admin Access.
If you are using a Pfsense Firewall, then you are probably aware that access to the management interface is allowed by default from all interfaces except the WAN
. To enhance the security of your network, in many environments access to the management interface should be limited with the use of firewall rules. For reasons as to why, see the blog post Securely Managing Web-administered Devices. With that said, below we will detail the steps required to limit access to the Pfsense administrative interface using basic firewall rules. First we will want to completely restrict administrative access from interfaces such as DMZ
or WLAN
. This can be accomplished with the rule pictured below.
GWN
) interface.
LAN
interface allowing Pfsense management interface access from our management PC only and access for all others restricted. Below you will note that we have two rules, the first of which allows access to the management interface from the management PC and the second that restricts access to all others. 
Note: The rules detailed above will break your firewall if you are using squid as a transparent proxy.