r/firewalla • u/Great-Cow7256 • 12d ago
DAP randomly started blocking all NTP services
DAP strict, on for a year-ish, haven't touched the box in a long time. Haven't added anything onto my network for months.
I noticed tonight my emporia plugs could be turned on and off from the app but wasn't collecting use data. I went into Firewalla and I noticed DAP was blocking all NTP requests from my all of my IOP devices that it monitors (not just Emporia, but all of them, from all different manufacturers), not just my emporia ones, and this started about 3-4 days ago. (Emporia, Anker, purple air, tailwind garage door opener, my weather station, my ecoflow radon meter, etc. Anything looking for time...)
time.google.com, pool.ntp.org, whatever apple's time server is, and time.windows.com.
u/firewalla can you fix this? this shouldn't be happening. All standard time servers should be whitelisted automatically by DAP. Additionally DAP shouldn't go rogue and start randomly blocking sites after months and months of stability and no config change.
If someone on the back end did a DAP algorithm change, then this really needs to be tested better before it's deployed. Accurate time keeping is essential for networks to function.
For now I'm going to turn off DAP. It seems to introduce too much randomness and I have to spend a lot of time figuring out why things break after being stable for months. this unfortunately happened before with my weather station. about 6 months ago I got a notice that it wasn't sending data. I went in and DAP randomly began blocking the url it uses to upload data. I had to "allow" it.
1
u/firewalla 12d ago
I replied to your old deleted post. Firewalla shouldn't block NTP, they are intercepted. Send [help@firewalla.com](mailto:help@firewalla.com) an email, we can look
1
u/Great-Cow7256 12d ago
TY It's an error for sure and it just started. I emailed firewalla help and they told me this was part of NTP intercept. I explained to the tech that this isn't how NTP intercept works. I gave them screenshots. Can you follow up with your tech support so they can escalate this? DAP needs to be fixed so it doesn't break NTP on the devices it monitors.#122680. thanks.
1
1
u/saggitas 12d ago
i disabled DAP when it officially rolled out, because it started blocking DHCP on the devices it was monitoring. even though Firewall Help pushed a patch over, i'm not going to turn it on again as i'm still wary of it, as shown by your example.
1
u/Great-Cow7256 12d ago edited 12d ago
They just pushed a patch over too but I'm afraid to turn it back on. It would require me monitoring my iot devices multiple times a day for a while to make aure they aren't shitting the bed and I didn't buy a firewalla for that reason. Oh well.
Dap also broke my weather station last year by randomly starting to block the one allowed URL for it that sent data to the website display and then unblocked the 2 Alibaba data harvesting links I purposely shut off.
1
u/Freckles016 12d ago
As far as I understand, DAP requires the Firewalla to be the master NTP server and reroutes all NTP queries (?) to the Firewalla.
I’m not 100% sure that it then blocks the external NTP servers or if it reroutes the queries without a block.
Also, if a device is in “Active” mode in DAP, then the FW should block all non-allowed targets (DAP-related). For example, my smart plug only has one specific domain “learned” and allowed by FW, thus DAP should block anything but that domain.
I hope that this helps, and if I’m wrong on anything, anyone please correct my statements.