Interface Access Denied
Interface Access Denied can interrupt web access, policy enforcement, or evidence collection. Use this runbook to restore service, preserve logs, and prove the corrective action during security review.Issues
Administrators can be locked out when creating or reordering policies in the Access Restrictions section. The browser then shows Access Denied.Root causes
SafeSquid evaluates Access Restrictions entries top to bottom and matches each entry to the connection. After an entry matching the connection’s IP or username is applied, later entries are not evaluated for that connection. When creating or editing entries, ensure at least one entry allows access to the web interface (http://safesquid.cfg/ - an embedded Rest UI interface built into SafeSquid, NOT resolved by DNS): an entry that matches the administrator’s connection and has Web interface (Config) selected in the Access field. Example: Scenario: three entries in the Allow list of Access Restrictions:- First entry: access the web interface via SSH tunnel.
- Second entry: allow the AUTHENTICATION BYPASS profile.
- Third entry: the entry used for general internet access.
Capture useful evidence
Collect evidence before restarting services or changing policy. Keep screenshots, command output, and relevant SafeSquid logs with the incident ticket.Next steps
- Use Find a complete connection log to trace a specific client transaction.
- Use Troubleshooting for the broader diagnostic checklist.

