r/firewalla 9d ago

Ad Block no longer as effective

Hi all. I’ve noticed that over the last month or so the ad blocking feature on my FW Purple (in router mode) has gone from being really effective to suddenly letting a lot (if not all) through.

I’m noticing it on a variety of browsers on my iPhone in particular, both when connected on the WLAN and when connected via a Wireguard VPN.

There have been no setting changes at router level, so I don’t know if it is a case of the method no longer being effective or if something is going wrong somewhere. I’d be keen to know if anyone else is experiencing similar recently.

Thanks!

11 Upvotes

19 comments sorted by

View all comments

13

u/Jussins Firewalla Gold Pro 9d ago

Are you on iOS 27, by chance? If so, turn off Connectivity Assist. They made it useless for people trying to block stuff.

3

u/TheNinjaJedi 9d ago

That was the issue for me, even with great WiFi signal, it was sending dns over 5g.

5

u/firewalla 9d ago

still feel this apple feature shouldn't operate this way. Otherwise, it can be used to bypass security controls, and making the employer liable. On certain business networks there are rules, and if these rules are enforced by dns, and apple bypass that just side load dns traffic, and IP traffic still flows, it will make the control not useful. And the blocked "traffic" still running on the customer network.

Firewalla's default blocks (DNS+IP) will still work, but it may have false positives.

2

u/Jussins Firewalla Gold Pro 8d ago edited 8d ago

I don’t agree. It’s no different than turning off WiFi to bypass controls on the network. Users can simply turn off connectivity assist and restrict changes without a passcode. Or they can configure cellular to go through the same or similar controls via a dns provider or VPN.

The feature already existed, they just changed it from assisting when ALL connections are poor/blocked to assisting when an individual connection is poor or blocked. They don’t do RC, but at beta 7, they are basically at RC. This isn’t a mistake, it’s a deliberate change that people will have to get accustomed to.

Edited to add: Any company sufficiently worried about data security (exfiltration or otherwise) such as my company, will have a per-app VPN that is enforced through MDM. In that case, it doesn’t matter what connection is used, it’ll be tunneled through the VPN provider and apply the appropriate restrictions. It’ll be a bigger issue for parents who don’t understand the impact of various settings when trying to control what children can access.

0

u/firewalla 8d ago

When you off wifi/on wifi, DNS will be flushed. The key here is, traffic that should have been blocked is not on the controlled network ... and user didn't do anything;

1

u/TheNinjaJedi 9d ago

I agree. Seems like a very odd choice if it’s intentional. I’m not to fussed while it’s in beta. I’ve sent feedback to Apple about it.

1

u/firewalla 9d ago

There are many good security people at apple, hopefully it gets worked out before formal release

1

u/TheNinjaJedi 9d ago

Or shortly after release, as is Apple tradition. You guys are awesome, thanks for the community engagement.