Support

Admin Tools

#34785 Locked out from backend when Admin Tools is enabled

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 08 April 2021 20:17 CDT

Bibbi

On some of my sites I have great problems with Admin Tools as I am very often locked out from backend and sometimes also from frontend. Very time I disable Admin Tools via FTP according the the guidelines, but when I then rename main-disable.php to main.php file, I am locked out again.

I am using a secret word in the url, and I have whitelisted my IP address.

Quite often I am only able to get access from my IP address, and if I try from another IP address, I will be locked out from backend and frontend.

I have followed all the guidelines as to the set-up, but how can I solve the problem?Β 

nicholas
Akeeba Staff
Manager

I am using a secret word in the url, and I have whitelisted my IP address.

Quite often I am only able to get access from my IP address, and if I try from another IP address, I will be locked out from backend and frontend.

What you describe is perfectly normal if you are using the IP whitelist. As noted in the interface and the documentation, when you use this feature you can ONLY access your site's backend from an IP address in the whitelist. Trying to access it from any other IP address counts as a blocked request. Toop many blocked requests and the IP is temporarily blocked from accessing the site completely.

The solution is to NOT use the IP whitelist. Remember that the IP whitelist only makes sense if you are only ever going to be accessing your site's backend from a set of known static IPs, nowhere else whatsoever.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Bibbi

I have NOT added my IP address in the 'Administrator Exclusive Allow IP List' or activated this feature, but have entered it in the 'Exceptions/Never block these IPs'.

Β 

nicholas
Akeeba Staff
Manager

All right, it was not very clear the way it was phrased before.

In this case I need to know what is the Target URL and Reason listed for your IP address in the Blocked Requests Log after you are blocked from accessing your site.

If you do not see your IP but a bunch of identical or similar IPs please let me know what these IPs are. It is possible that your site is behind a CDN or reverse proxy but your web server is not configure to pass the forwarded IP address to PHP. In this case Admin Tools would be seeing the wrong IP address. There is a simple workaround for that but it's only safe to enable if and only if your server is actually affected by a configuration like this.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!