Support

Admin Tools

#27895 backend and frontend locked out

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 30 June 2017 17:17 CDT

miwa
 Hi,

I am using admin tools and I put the IPs for superadministrator to the white list. Although I did this, admin tools locks me out of the site also out of the backend.

It is an onlineshop. So the question is does it also lock out the poeple who wants to do an order? Do I have to configure something there? And why does it lock me out of the site although my IP is listed on the white list?

URL: www.bettervitalshop.de

Thank you.

Best regards

dlb
Yes, it is possible that the issue could affect customers. I think you have a setting wrong, which is the root of the problem. Go to Web Application Firewall, Configure WAF, on the first tab, switch the "Enable IP workarounds" setting. If it is checked, uncheck it, if it is unchecked, check it. This changes the way the IP addresses are handled when forwarded from CloudFlare or a similar software in front of your web server. Admin Tools tries to figure out how it should be set, and it succeeds most of the time, but once in a while it is wrong.

Then you need to clear the blocked IP address and Security Exceptions log.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

miwa
Ok. I did this.

But when I try to access the backend via: www.domain.de/administrator, then it goes back to www.domain.de. And the backend cannot be accessed. :-(

dlb
You need to disable Admin Tools with the instructions here: https://www.akeebabackup.com/documentation/troubleshooter/atwafissues.html. That will allow you to log into the back end of your site. Go to Web Application Firewall, Configure WAF, on the first tab, is there something in the Secret URL parameter field? If there is, you need to call your administrator login page with a different URL, www.mysite.com/administrator/index.php?secret. Where "secret" is the contents of the field. If you leave that field blank, the feature is turned off and the normal URL will work.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!