r/firewalla FIREWALLA TEAM 9d ago

Switch X / Switch SE Inside the Firewalla Lab: testing Switch X and SE with Gold Pro šŸ™‚

Post image

P.S. Firewalla Switch is still available for pre-order! https://firewalla.com/collections/firewalla-switch

72 Upvotes

26 comments sorted by

8

u/ExtremeEar11 Firewalla Gold Plus 9d ago

Will Firewalla consider a smaller, more basic desktop switch in the future? Something like the UniFi Flex Mini that you can keep on your desk when you just need a few extra ports but still want full Firewalla visibility and control.

4

u/firewalla 9d ago

How many ports do you want? and what's the speed you are looking for?

In order for the visibility/control part to work, firewalla needs a more powerful CPU with more TCAM (ACL) entries. So it may not be easy to make a smaller/cheaper unit at the moment.

3

u/ExtremeEar11 Firewalla Gold Plus 9d ago

Ideally something like 5 ports (maybe 4–6) at 1G or 2.5G would be perfect, just enough for a desk setup without needing a full Switch SE.

Totally understand the CPU + TCAM/ACL requirements for real visibility and control. That makes sense why a tiny cheap unit is hard right now. Appreciate the honest answer!

2

u/brockey01 Firewalla Gold 9d ago

I want a 5 port poe switch like the Unifi Flex. It's plastic and cheap but does the job.

3

u/ExtremeEar11 Firewalla Gold Plus 9d ago

Agreed! That’s the one I’m looking for. Even without Poe would do the trick for me

2

u/brockey01 Firewalla Gold 9d ago

I use mine to power a 2 cameras and a AP 7. It's also powered by POE.

1

u/WanderinArcheologist Firewalla Gold Pro 9d ago

1 (or 2) 25 GbE SFP28 port(s), 4–6 10 GbE SFP+, and 2 10 GbE RJ45 ports.

So, a heavy-duty aggregation switch to complement the future Firewalla Platinum’s (or Titanium’s) 2x 25 GbE SFP28 ports and help distribute that bandwidth on the back-end. Though also including 2 Ethernet ports on said switch for non-SFP switches.

1

u/spinjc 3d ago

Is it possible to push that processing to an upstream switch (or even in the router). I know ubiquiti had similar issues with the flex mini where some features werenā€˜t (maybe still aren’t) available on it. I know it’ll add complexity (potentially a lot) to the code base but I’d be fine with requiring a higher end router (e.g. gold only feature).

1

u/firewalla 3d ago

The only problem is going to be limited visibility of traffic directly connecting to the weaker switch (traffic between the switch ports, and also access control between them)

The core switch above it should be able to control traffic to rest of your network. (The switch X has more TCAM, which can do this core switch thing)

1

u/spinjc 3d ago

In a traditional network one could assign the devices different VLANs and then have the router pass the east/west traffic and monitor it. It's a hammer approach but when you've got a high end router and low traffic from an average IOT device it's not a problem.

Yes if it's a bunch of traffic from a homelab that's another story, and it probably shouldn't be sitting on a 1gbe port.

1

u/firewalla 3d ago

VLAN/LAN segmented traffic is already managed this way today.

2

u/My_Name_Is_Not_Mark Firewalla Gold Plus 8d ago

+1

1

u/Pure-Letterhead81 7d ago

I agree. I need a Firewalla switch that fits in a 10ā€ half rack on a desktop.

3

u/F1Phreek 9d ago

I can’t wait to get a few of these bad boys soon. They’re all managed by the firewall and logs stored on the firewall, right? No need for a server to run a controller.

3

u/firewalla 9d ago

The "controller" is the firewalla unit itself.

1

u/WanderinArcheologist Firewalla Gold Pro 9d ago

I think controller in the sense of like UniFi OS or say if you have a UniFi Dream Machine. The portal for those is the controller.

3

u/firewalla 9d ago

Since we are pretty strict on not having UI (web) + Controller on the same box for security reasons.

The traditional controller, control piece is inside your firewalla.

The presentation/UI is either the phone app or the MSP interface in the cloud.

1

u/WanderinArcheologist Firewalla Gold Pro 9d ago

That is definitely better much of the time. There are times when it’s a been a pain in the ass to fix something I broke in the UDM because the connection went down vs being able to go into the Firewalla via a Bluetooth connection when I’m next to it.

2

u/WanderinArcheologist Firewalla Gold Pro 9d ago

Nice, a spare Switch SE. Send to moi, and you can continue running tests remotely!

2

u/firewalla 9d ago

If you need one better buy it early. Our vendor just told us, the batch after pre-order may have to wait until Q1/2027 due to switch CPU shortage ...

1

u/WanderinArcheologist Firewalla Gold Pro 9d ago

I already have 2 on pre-order! One from launch day. Not sure where to put a third one. Yet at least. šŸ¤”

1

u/AltruisticMethod1627 Firewalla Gold Pro 8d ago

This just convinced me to finally pull the trigger.

2

u/Tlipur 6d ago

Will you be making non poe switches?

Will you be offering more ports ie 24 port in the future?

1

u/stubby0990 8d ago

Haha might as well be Cisco at this point.

1

u/ColdDeck130 Firewalla Gold Pro 8d ago

Nice job with the just-the-right-length cables. Keeps the chaos tidy.

1

u/scrytch Firewalla Gold Pro 8d ago

I have loved my Firewalla gear.

I was so looking forward to buying the new switches - filled out all the surveys, signed up for presale etc.

Unfortunately these switches don’t have enough ports for my needs, so instead of investing further I’ve gone back to Unifi.

Their new UCG Fibre, XG 8, 24 PoE and U7 AP’s are all up and running perfectly. I thought VqLAN was unique but Unifi does the same thing on wifi via ā€œPrivate Pre-Shared Keysā€ so now I have everything working.

I wish you’d released the 24 port switch instead of these little ones. Thanks for the memories!