This is a joke, I didn’t really lock myself out

  • rmuk@feddit.uk
    link
    fedilink
    English
    arrow-up
    17
    ·
    5 days ago

    I’ll always be grateful for the firewalls like OpenWRT that will automatically revert any changes if you don’t log back in after a few minutes (at least on the web interface). I’m not proud of how many times that’s saved me.

  • mavu@discuss.tchncs.de
    link
    fedilink
    arrow-up
    111
    ·
    7 days ago

    even worse. I regularly have to get up out of my chair and go down 2 stairs.

    Also this took a while to find, but : https://sourceforge.net/p/shorewall/svn/HEAD/tree/branches/4.2/Samples/one-interface/shorewall.conf

    ADMINISABSENTMINDED=Yes

    Is an actual setting in the config for the (now apparently unmaintained) Shorewall Firewall software/tool for linux.

    If I remember correctly, it always checks on firewall rule changes if there is an active connection on port 22, and adds a special rule at the end to maintain that connection.

    They don’t build them like they used to anymore.

    • Jankatarch@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      edit-2
      6 days ago

      They don’t build them like they used to anymore.

      Well if we did, the way it works would be by telling a chatbot to enable ssh on port 22 at the end.

  • piefood@feddit.online
    link
    fedilink
    English
    arrow-up
    73
    ·
    6 days ago

    Before you make a change, do this in a screen-session:

    sleep 300 && iptables-restore old_fw_rules.bak

  • randint@lemmy.frozeninferno.xyz
    link
    fedilink
    English
    arrow-up
    66
    ·
    7 days ago

    Almost the same thing happened to me. I accidentally fucked up the internet connection in my home while in Japan, and I had to video call my mom to have her fix it. It was a pain for both of us, but thankfully it went rather smoothly. Thank you mom!

      • Honytawk@feddit.nl
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        5 days ago

        Most corporate network devices like Cisco will reset their config to the one written in memory when they lose power.

        So in that case, just unplug and replug them to restore to previous config.

        Just make sure you write your new config to memory or it will reset when there is ever a power failure.

      • randint@lemmy.frozeninferno.xyz
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 days ago

        So I connected through ssh back home to fiddle with the router settings, and in the PPPoE settings (where you set a pair of username and password that your router sends to the ISP such that the ISP knows you and knows what IP to assign to you) I made a typo, and apparently that instantly killed the internet connection at home and also for me. I had to call my mom to instruct her to fix the typo in the username. TBH I don’t know that much about PPPoE either, I only do it so that the ISP assigns us the same IP address every time.

    • qaz@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      62
      arrow-down
      1
      ·
      edit-2
      7 days ago

      I’d rather plug in a screen with VGA than deal with HPE iLO 4

      • NeilBrü@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        11 hours ago

        Networking noob here; what, pray tell, is HPE iLO4… or do I want to even know?

        Edit: Never mind. Found it. HP… shudders

        • buttnugget@lemmy.world
          link
          fedilink
          arrow-up
          8
          ·
          6 days ago

          “In December 2021 Iranian researchers at Amnpardaz security firm have discovered rootkits in HPE’s iLO (Integrated Lights-Out) management modules.”

          Because of course lol

      • dbtng@eviltoast.org
        link
        fedilink
        English
        arrow-up
        5
        ·
        6 days ago

        I keep a Windows 2008 w Java 6 VM on ice for administering old Java console shit like that.
        The VM is unsafe as hell. Completely virgin unpatched. The only protection is that I don’t give it a gateway or dns, and I shut it down when its not in use.
        And it works. Old Java shit can still be used.

      • mkhopper@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        7 days ago

        To be honest, HPE iLO 6 isn’t too bad, if you’re using the GUI. It’s the API that remains really broken in many places.

      • Appoxo@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        6 days ago

        Sounds like an issue draling with .NET or JRC console.
        Are you on the nosz up to date firmware?

        • qaz@lemmy.worldOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 days ago

          I remember there being the option of using HTML or a Java applet, I chose the former

          • Appoxo@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            4
            ·
            6 days ago

            If you have the HTML5 option you should be on a pretty recent firmware.

            Interesting that you’d prefer going (literally) analog connection rather than over the IPMI.

              • Appoxo@lemmy.dbzer0.com
                link
                fedilink
                arrow-up
                2
                ·
                6 days ago

                You know, I wanted to say “Bet!” and proove your wrong as I couldnt believe they never went past 2023 for the firmware.
                Turns out that was the latest.

                But I do know they have more recent firmware uploads for the UEFI than 2023. ^(A year younger but no less nore recent/s)

  • Björn Tantau@swg-empire.de
    link
    fedilink
    arrow-up
    36
    arrow-down
    1
    ·
    7 days ago

    Classic.

    Love Hetzner. If something like that were to happen to me they can hook up a remote console accessible through their web interface.

  • medem@lemmy.wtf
    link
    fedilink
    arrow-up
    26
    ·
    edit-2
    7 days ago

    Since that happens to the best of us, I envision writing a wrapper script around {n,}pfctl that asks for confirmation upon detecting that you’re logged in via ssh through a specific port AND detecting that the new rules would block that port.

    • dbtng@eviltoast.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      VMware does this with its virtual networking. If a change takes it offline, it automatically rolls it back. It can be frustrating at times, but mostly its saved my ass.

      • Honytawk@feddit.nl
        link
        fedilink
        arrow-up
        1
        ·
        5 days ago

        Meraki does this as well. If you change anything that might disconnect the uplink or the port you are connected to, it gives you a pop-up warning before it commits.