Support

Admin Tools

#24391 Web Appication Firewall

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Monday, 08 February 2016 20:36 CST

jdmorris
I tried configuring the firewall keys a few times, without success, I keep getting locked out?
Even with the Administrator secret URL parameter "test": I log in with my url and /administrator/index.php?test
No luck? I do get sent a message and it reverts to my home url.
I read the work around and disabled the main.php, then re-enabled it and tried again...etc.
I am using RSFirewall, so I'm wondering if this is causing a conflict?
I tried leaving the Administrator secret URL parameter blank and I still get locked out.
I added my IP to the Whitelist to insure that wasn't affecting anything.
Any ideas as to why this is locking me out?

dlb
The whitelist doesn't do what it sounds like it does. This is used in connection with another option and will block everyone from accessing the back end of the site except those in the whitelist. The option you want is "Never block these IP addresses". That keeps you from getting blocked.

You need to clear your IP address, there should be a red button on the Admin Tools Control Panel page that will do that for you. If you don't clear it, you just keep getting locked out over and over.

I can't tell you why you're getting locked out. The answer is in the Security Exceptions Log under Web Application Firewall. It sounds like you're doing things right.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

jdmorris
Hi Dale,

There are no IP Address in the Auto IP Blocking History or Auto IP Blocking Administration?

Is there a way to disable the Web Application Firewall until I sort this out?

Thanks,

John

jdmorris
Dale,

I just figured out what was happening...I had something (a space or period) in the Change administrator login directory to field, it must have been conflicting with the Administrator secret URL parameter.

Cheers,

John

dlb
John,

I'm glad you figured it out! That's the kind of thing that would have had us all pulling our hair out.

Yes, you can disable the System - Admin Tools plugin to disable everything except any changes to the .htaccess file (if you have run .htaccess Maker).


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!