Julio If you have already placed an interface as the main one and it has the orange tag indicates that the web interface has an ip for socket connection. Another option that should be taken into account is permission to access the SSH protocol in Loopback ip.
To do this you can create a Zone Protection on Services >> Firewall >> Zone Protection >> +, with the following conditions:


This will allow the service to perform an SSH connection on the loopback IP and consequently open the shell web terminal.
Or, if you want to make it more restricted, create an IPv4 object with your LAN networks and add it as source instead of using the 'Reserved Classes'.
Note: It is important to highlight that it is not recommended to create a rule with the 'All' zone without having a defined 'Origin' object.
If even after following this procedure the rule does not take effect, we suggest you contact our support team for further investigation.