Page 1 of 1

Restrict admin access to LAN

Posted: 10 Sep 2009, 14:37
by snis
If you want to restrict your Bubba admin interface (http://bubba/admin) to you local LAN and not having it enabled on the WAN for the rest of the world to see, this guide might be for you.

Using ssh, log on to Bubba (as your regular user). To become root Type:

Code: Select all

su -
And enter the password:

Code: Select all

If you haven't changed the default, that is.

Edit your the admin part of the Apache config:

Code: Select all

nano /etc/apache2/conf.d/admin.conf
You will find the part <Directory /usr/share/web-admin/admin>, change it to:

Code: Select all

<Directory /usr/share/web-admin/admin >
        AllowOverride None
        Order Deny,Allow
        Deny from all
        Allow from
        DirectoryIndex index.php
        AddHandler php-cgi .php
        Action php-cgi /fcgi-bin/php.cgi virtual
Observe that the network should match the network you have on your LAN. If you are unsure can find it under:

Code: Select all

For example: your IP address is: and your netmask is, then the Allow from should be:

Code: Select all

Allow from
After you have edited the file, you have to reload Apache to reflect the changes. Type the following:

Code: Select all

/etc/init.d/apache2 reload
This change will likely be overwritten and changed back to the defaults if you upgrade your Bubba

If you have any better ways of doing this, please let me know..

Re: Restrict admin access to LAN

Posted: 13 Sep 2011, 13:20
by drdr6
I tried this and after the change no users at all seem to be able to log in from outside

Pretty much the first thing that Forum won't this-forum-won't-allow://mydomain redirects (on its own to) is this-forum-won't-allow://mydomain/admin and then says "Forbidden"


Re: Restrict admin access to LAN

Posted: 14 Sep 2011, 12:36
by Ubi
how strange that you found absolutely no help in the log files about this problem, even after extensively searching through them.

Re: Restrict admin access to LAN

Posted: 14 Sep 2011, 13:40
by Eek
I have not tried it, but should it not be

Code: Select all

        Order Allow,Deny
        Allow from
        Deny from all