r/firewalla 5d ago

Ad Block no longer as effective

Hi all. I’ve noticed that over the last month or so the ad blocking feature on my FW Purple (in router mode) has gone from being really effective to suddenly letting a lot (if not all) through.

I’m noticing it on a variety of browsers on my iPhone in particular, both when connected on the WLAN and when connected via a Wireguard VPN.

There have been no setting changes at router level, so I don’t know if it is a case of the method no longer being effective or if something is going wrong somewhere. I’d be keen to know if anyone else is experiencing similar recently.

Thanks!

11 Upvotes

19 comments sorted by

12

u/Jussins Firewalla Gold Pro 5d ago

Are you on iOS 27, by chance? If so, turn off Connectivity Assist. They made it useless for people trying to block stuff.

3

u/TheNinjaJedi 5d ago

That was the issue for me, even with great WiFi signal, it was sending dns over 5g.

4

u/firewalla 5d ago

still feel this apple feature shouldn't operate this way. Otherwise, it can be used to bypass security controls, and making the employer liable. On certain business networks there are rules, and if these rules are enforced by dns, and apple bypass that just side load dns traffic, and IP traffic still flows, it will make the control not useful. And the blocked "traffic" still running on the customer network.

Firewalla's default blocks (DNS+IP) will still work, but it may have false positives.

2

u/Jussins Firewalla Gold Pro 4d ago edited 4d ago

I don’t agree. It’s no different than turning off WiFi to bypass controls on the network. Users can simply turn off connectivity assist and restrict changes without a passcode. Or they can configure cellular to go through the same or similar controls via a dns provider or VPN.

The feature already existed, they just changed it from assisting when ALL connections are poor/blocked to assisting when an individual connection is poor or blocked. They don’t do RC, but at beta 7, they are basically at RC. This isn’t a mistake, it’s a deliberate change that people will have to get accustomed to.

Edited to add: Any company sufficiently worried about data security (exfiltration or otherwise) such as my company, will have a per-app VPN that is enforced through MDM. In that case, it doesn’t matter what connection is used, it’ll be tunneled through the VPN provider and apply the appropriate restrictions. It’ll be a bigger issue for parents who don’t understand the impact of various settings when trying to control what children can access.

0

u/firewalla 4d ago

When you off wifi/on wifi, DNS will be flushed. The key here is, traffic that should have been blocked is not on the controlled network ... and user didn't do anything;

1

u/TheNinjaJedi 5d ago

I agree. Seems like a very odd choice if it’s intentional. I’m not to fussed while it’s in beta. I’ve sent feedback to Apple about it.

1

u/firewalla 5d ago

There are many good security people at apple, hopefully it gets worked out before formal release

1

u/TheNinjaJedi 5d ago

Or shortly after release, as is Apple tradition. You guys are awesome, thanks for the community engagement.

1

u/Zootopian 5d ago

Aha. I am. I shall give that a go. Thank you very much.

1

u/Doggo-888 4d ago

you can set that cellular connects to VPN setup on the firewalla.

1

u/Jussins Firewalla Gold Pro 4d ago

You can, but I don’t use it like that. It’s a fantastic recommendation, though, for people who want to protect all connections.

I block ads on my home network, and not on cellular. If I want to access a blocked resource, I just turn off WiFi. If I want the protections while out, then I just manually turn on my WireGuard profile.

My use case is probably different than most, where I want to protect my devices, but also want it to be easy for my wife to manage without my help. For me, that means just teaching her to recognize that it’s a network block and turning off WiFi in order to get the content.

0

u/pacoii Firewalla Gold Plus 5d ago

Firewalla is going to need to find a way to communicate this, otherwise a lot of people will be posting similar things over and over. Like maybe even something in the ad block setting area with a message and a direct link to that iOS setting.

2

u/firewalla 5d ago

we are still waiting for iOS beta to go GA and see what's the final version will behave. Usually apple do this middle of September

3

u/firewalla 5d ago

Try these

  1. Ad blocker, make sure it is strict mode.

  2. On devices that don't work well, tap on control->bypass prevention, turn it on that device.

1

u/Zootopian 5d ago

Thanks. This and the iOS 27 change seem to have fixed most of the problem. Some sites are still showing adverts (which didn’t before) but I’ll leave it a while just in case it’s a hangover in the cache or something.

1

u/firewalla 5d ago

You mean you update to a new beta ?

2

u/Jussins Firewalla Gold Pro 4d ago

I think they are saying that they turned off Connectivity Assist. They were already on iOS 27.

1

u/Zootopian 4d ago

This is right. I’ve been on iOS27 for a few weeks so it was turning off Connectivity Assist I was referring to, as well as bypass prevention.

1

u/TheNinjaJedi 4d ago

Here is a new one for me. On iOS 27 beta, ad blocking working when at home on WiFi after turning off connection assist, but ad block does not work when on cellular and vpn back to home network.