PfSense Console Configuration on MTN Cloud
PfSense console Administration & CLI Tools
Overview
The MTN Cloud Console provides low-level administrative access to your virtual security and gateway appliances. This guide serves as a technical reference for network engineers and systems administrators to manage interfaces, configure secure site-to-site tunnels, control background daemons, and run real-time packet diagnostics directly from the command-line interface (CLI).
Prerequisites
Before running console operations, ensure you have:
- An active SSH connection or direct terminal session to your cloud gateway.
- Administrative or root credentials for the appliance.
- Baseline familiarity with FreeBSD-based networking environments and packet filtering logic.
Part 1 – Primary Console Menu & VPN Setup
WireGuard VPN Deployment Methods
If your deployment topology requires an internal site-to-site VPN tunnel, you can implement it using one of two architectural approaches:
- Method A: Internal WireGuard Container Deploy the WireGuard package natively inside your gateway instance by executing this command in the terminal:pkg install -y pfSense-pkg-WireGuard
- Method B: External WireGuard Routing If running WireGuard on a dedicated standalone server within your internal private network:
- Confirm a successful cryptographic handshake in your external WireGuard instance status.
- Ensure UDP Port 51820 is explicitly forwarded on the MTN VPN WAN interface.
- Create a Static Route mapping the remote subnet directly to the private IP address of your internal WireGuard server.
Step 2 - Fill in Required Fields
Upon initial authentication, you are presented with a guided, interactive management menu. These numerical options allow you to perform immediate system maintenance and recovery tasks without entering a raw shell:
- Logout: Safely terminates the current active SSH session.
- Assign Interfaces: Re-maps physical host ports (e.g., igb0) to logical segments like WAN or LAN.
- Set interface(s) IP address: Configures static local IPs or toggles DHCP client mode on the WAN. This is your primary recovery mechanism if you lose web GUI access.
- Reset admin account: Automatically reverts the admin password back to its factory default (cloud) and restores group privileges.
- Reset to factory defaults: Completely purges custom configurations and triggers a fresh system reboot.
- Reboot system: Power-cycles the security gateway appliance.
- Halt system: Cleanly shuts down the underlying operating system.
- Ping host: Sends basic ICMP echo requests to verify upstream network layer connectivity.
- Shell: Drops the administrator out of the menu and into a native FreeBSD command-line prompt.
- pfTop: Launches an interactive tool providing real-time visibility into firewall connection states and throughput.
- Filter Logs: Streams a live view of raw firewall packet processing events directly to the console screen.
- Restart webConfigurator: Recycles the Nginx web server engine and PHP-FPM pool. Run this immediately if the web dashboard becomes unresponsive.
- PHP shell + MTN Cloud tools: Spawns an interactive PHP sandbox tailored for developers and advanced diagnostic script execution.
- Update from console: Checks upstream repositories and runs system updates directly over the CLI.
- Enable/Disable Secure Shell (sshd): Toggles the local SSH daemon listener on or off.
- Restore recent configuration: Rolls back system parameters to automated backup checkpoints taken by the environment.
- Restart PHP-FPM: Exclusively recycles the PHP backend worker processes, which resolves common web dashboard 502 Bad Gateway errors.
Part 2: Command Line MTN Service
Playback Framework (pfSsh.php)
For system administration scripts and automated overrides, use the platform’s native playback engine:
- changepassword:Interactively prompts to reset an individual operator’s password if locked out.
- disablecarp / enablecarp: Temporarily takes High Availability cluster synchronization offline, or brings it back online.
- nohttpreferercheck: Disables browser HTTP Referer header verification. Useful if you are experiencing dashboard access blocks while managing the unit through tight proxy networks.
- enableallowallwan: Injects a temporary firewall rule allowing all inbound traffic on the WAN interface. Warning: Enforce this only during extreme, isolated troubleshooting scenarios!
- external_config_locator: Forces the platform to scan external storage or USB drives to locate a valid config.xml file for emergency system recovery.
- gatewaystatus: Dumps real-time latency, jitter, and packet loss statistics for all active gateways.
- generateguicert: Automatically provisions a fresh, self-signed SSL certificate to patch broken WebGUI HTTPS configurations.
- gitsync: Syncs custom engineering platform scripts directly with official development repositories.
- installpkg / uninstallpkg: Manually provisions or removes system packages directly via CLI (e.g., pfSsh.php playback installpkg openvpn-client-export).
- listpkg: Returns a complete directory of all available repository packages ready for installation.
- pfanchordrill: Recursively traces and enumerates the rules active inside hidden UPnP or NAT-PMP packet anchors.
- pftabledrill: Outputs the complete runtime content of internal firewall tables, including network aliases, bogons, and active blocklists.
- removeshaper: Sweeps the system clean of all active Traffic Shaper (ALTQ) quality-of-service profiles.
- resetwebgui: Reverts dashboard theme modifications and custom layout widgets back to factory layouts without wiping your underlying network rules.
- restartdhcpd / restartipsec: Quickly cycles the local address assignment daemon or resets secure IPsec VPN tunnels.
- upgradeconfig: Triggers a manual schema upgrade if the kernel identifies an outdated or legacy version of the system configuration file.
Service Control (svc)
Manage individual background system daemons using the specialized service wrapper syntax:
Supported Actions: start | stop | restart
Packet Filter Control (pfctl)
When you need to bypass abstractions and interact directly with the core packet filtering engine, execute the following parameters from the shell:
- pfctl -d: Disables all active packet filtering mechanisms, stripping the appliance down to a simple, un-firewalled Layer 3 router.
- pfctl -e: Instantly re-enforces the active firewall security policies.
- pfctl -f /tmp/rules.debug: Drops the running ruleset out of active memory and forces a clean reload from the specified debug file template.
- pfctl -s info: Returns high-level engine statistics, state tracking metrics, and memory utilization limits.
- pfctl -s states: Dumps the entire active connection tracking state table.
- pfctl -k <IP>: Instantly terminates all active connection states bound to or from a specific host IP address.
- pfctl -K <network>: Tears down all connection tracking entries associated with an entire CIDR network block.
- pfctl -s rules: Displays the live, compiled sequence of filtering rules currently applied to traffic.
- pfctl -s nat: Displays the running Network Address Translation rule mappings.
- pfctl -T show -t <table_name>: Enumerates all IP addresses currently compiled inside a targeted alias or network lookup table.
- pfctl -T flush -t <table_name>: Clears all IP mappings out of an explicit firewall table instantly.
Diagnostics & Troubleshooting Tools
Essential FreeBSD Network Commands
Standard Unix networking utilities are fully available to evaluate interface health and verify routing mechanics:
- ifconfig: Inspects hardware link status, interface flags, physical MAC addresses, and assigned VLAN tags.
- netstat -rn:Outputs the system’s live IP routing table.
- netstat -m: Scans memory buffer allocation (mbufs) to isolate or rule out network buffer exhaustion bugs under heavy traffic loads.
- netstat -i: Provides interface packet statistics, explicitly counting drop events, physical errors, and transmission collisions.
- arp -a: Dumps the local Address Resolution Protocol cache to resolve Layer 2 to Layer 3 hardware mappings.
- sockstat -l: Lists all listening sockets, showing bound network protocols and the specific Process ID (PID) managing each port.
- tcpdump -i <interface> -n: Sniffs raw packets traversing a specified interface boundary. (The -n flag bypasses automatic DNS lookups to eliminate packet-processing delay).
- ping / ping6: Executes diagnostic echo checks to check host reachability across IPv4 or IPv6 paths.
- traceroute / traceroute6: Maps the exact node-by-node path a packet follows to reach a destination target.
System & Hardware Diagnosis
Use these commands to isolate performance bottlenecks, hardware resource limits, or kernel anomalies:
- top -aSH: Launches a real-time process manager detailing system threads, precise CPU core usage, and individual hardware interrupt loads.
- pftop: Displays an auto-refreshing, state-centric connection load view directly reflecting firewall traffic distribution.
- vmstat -i: Aggregates and logs interrupt rates across hardware components. Unusual interrupt spikes on a single IRQ channel typically point to underlying hardware resource conflicts.
- clog /var/log/system.log: Reads the native system log. (Note: Platform logs utilize a circular ring buffer design; standard utilities like cat or tail will return corruption or formatting errors. Always pipe or view via clog).
- dmesg: Dumps the system boot message ring buffer to analyze kernel initialization trends and hardware detection logs.
- uptime:Displays the appliance’s continuous operational duration alongside running system load averages.
Advanced Command Utilities & Live Logs
Instant Rule Management (easyrule)
Inject firewall overrides directly from your terminal session using the platform’s fast-rule wrapper:
Shell Account Control
To force a credential update for a local account straight from the command line, run:
Live Diagnostic Streams & Logs
To read raw, unformatted firewall log data into a highly structured, clean human-readable output, pipe the log stream through the native filter parser:
Monitor live service states and application logs continuously by executing standard streams:
- DHCP Address Assignments: tail -f /var/log/dhcpd.log
- OpenVPN Session Events: tail -f /var/log/openvpn.log
- Global Kernel Security & System Events: tail -f /var/log/system.log