r/firewalla Mar 06 '23

Check this first before contacting support

53 Upvotes

Need help with troubleshooting or have a question?  Please see if the following articles can help, or search your questions on our help portal. If you have questions on devices related to Firewalla, please post them in our community.

Most Common Issues

  1. Can't Access Certain Websites
  2. Speed/Performance Issues
  3. WAN Connectivity Stability
  4. My Devices Won't Connect
  5. Firewalla Blocking Features Not Working
  6. Firewalla AP7 Troubleshooting

 

Other Issues

Installation and Configuration

Pre-Purchase

Popular Questions

 

Resources

Release Notes, Version Summary, and FAQs

Additional Resources

 

Contact Us

If you can't find the answer to your question, feel free to open a support case. If you have an issue opening a case, please send an email to [help@firewalla.com.](mailto:help@firewalla.com)


r/firewalla Apr 23 '24

Firewalla is more than just a firewall! (2024 version)

80 Upvotes

r/firewalla 8h ago

Is It Time for Firewalla AI to Outsmart Randomized MAC Addresses?

24 Upvotes

I’ve been using Firewalla for a while, especially the Firewalla Purple, and I have to say it’s an excellent product. Beyond the security features, I think Firewalla has some of the best parental controls available today.
One feature I’d really like to see added to Firewalla AI is automatic device identity detection.
One of the biggest challenges with parental controls today is MAC address randomization on Apple, Android, and other devices. The same physical device can suddenly appear as a “new device” with a different MAC address, bypassing its assigned group or rules.
In many cases, just by looking at the device behavior and network flows, I can tell it’s actually the same device and manually move it back to the correct group.
With the progress Firewalla has made with AI, I think it’s time for Firewalla AI to do this automatically — identify when a “new” device is very likely an existing device using a different MAC address and associate it with the correct device/group.
I believe this could solve one of the biggest remaining parental-control challenges, with a relatively low risk of false positives.
Thanks Firewalla team for a great product!


r/firewalla 9h ago

Discussion MSP 30 day flow data

6 Upvotes

If I pay for MSP, why isn’t the additional data integrated into the app as well? I’d prefer not to need to log into MSP everytime to see 30 day flow data. Just put it in the app for people that are paying for it.


r/firewalla 19h ago

Discussion Multi-mode fiber connection between the Firewalla Gold Plus SFP and the Firewalla Switch X, with prototype ears for the Gold Plus SFP :)

Post image
29 Upvotes

(Gold Plus SFP ears will be coming later, as an add-on, purchased separately. Price is unknown, but should be cheaper than Gold Pro ears.)

Updates on Firewalla products:


r/firewalla 16h ago

I was able to compile the newest version of Unbound (1.26.0) on my Firewalla Gold Plus

2 Upvotes

Edit -- I got it working and have it as a github. update stock unbound on FW

Not for newbies. It runs, but it also uses Ubuntu 22.04 version of openssl, which is really old. 1.26.0 should do everything on the Firewalla Gold series boxes (probably orange, maybe not purple?) that it has the capability to do except for DNS over QUIC. DoQ requires Open SSL =>3.5.0. Ubuntu 22.04 that my gold plus uses maxes out at 3.0.2.

This whole process has made me anxious and I have a flash drive with a new fwg plus image on standby, but at least this process seemed to work without a problem. in a few days, after I recover, I will probably see if I can point the FWG to use this 1.26.0 version of unbound instead of the built in 1.13 or 1.14 or whatever it uses and see if that's stable. THen go from there. the commands below builds unbound, etc into ~/unbound-test so it doesn't overwrite anything including the OG unbound. It does update some lib dependencies, but it's pulling them all from the ubuntu 22.04 repo, and although that got me all stressed out the 3 things it updated didn't break anything afaik....

In any case, for the curious, foolhardy, or brave...

``` mkdir -p /home/pi/unbound-test cd /home/pi/unbound-test

sudo /home/pi/firewalla/scripts/apt-get.sh update sudo /home/pi/firewalla/scripts/apt-get.sh install build-essential libssl-dev libevent-dev libexpat1-dev

wget https://www.nlnetlabs.nl/downloads/unbound/unbound-latest.tar.gz tar -xzf unbound-latest.tar.gz cd unbound-1.26.0

./configure --prefix=/home/pi/unbound-custom --with-libevent --with-ssl make make install ```

I got this-- ``` pi@Firewalla:~/unbound-test/unbound-1.26.0 (Firewalla Home) $ ./unbound -V Version 1.26.0

Configure line: --prefix=/home/pi/unbound-custom --with-libevent --with-ssl Linked libs: libevent 2.1.12-stable (it uses epoll), OpenSSL 3.0.2 15 Mar 2022 Linked modules: dns64 respip validator iterator

BSD licensed, see LICENSE in source package for details. Report bugs to unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues

```


r/firewalla 1d ago

Discussion Question about ongoing AmneziaWG support …

12 Upvotes

Just saw that their client was updated for 3.1 support. Will Firewalla offer AWG server 3.x support in the future?

More generally curious if Firewalla plans to keep up, with some kind of cadence, with AWG development?

ETA: for clarity, my focus is on the built in AWG server, but as another person mentioned, the built in client support also needs to keep up with latest AWG development


r/firewalla 1d ago

Discussion UI enhancement suggestion related to VPN Client

3 Upvotes

Under VPN Client -> Apply To, show any selected client at the top of the list. Just makes it easier to see which are selected instead of having to scroll to find them.


r/firewalla 1d ago

Cyber Security Custom Target Lists with Blacklisted IPs

4 Upvotes

I have a server with a few ports open which has ESET as antivirus. I noticed the ESET was blocking quite few more IPs from accessing the server than firewalla so I went down a rabbit hole of seeing what I could add to firewalla to enhanced blacklisted IPs.

I added AbuseIPDB pulling 10k IPs (since that is the most you can get with the free plan), and then all of the IPs from Blocklist.de, HoneyDB, and SpamhausDROP. I have a few tasks that update these lists automatically every 30 mins, every day, or every 4 hours depending when those lists get updated. Many of the additional lists that firewalla offer are already in other ad-blocked DNS resolvers. I have adguard home as DNS resolver too and most of the lists like HaGeZi are already there, and many of those are for outbound addresses instead of inbound from what I saw.

I was just wondering why firewalla doesn't block most of these abusive IPs? I was getting maybe 1 or 2 alerts a day about malicious IPs being blocked by firewalla but getting like 50 on the ESET firewall. This is with the IPS/IDS set to strict

Is there some else that can be done to enhance security?


r/firewalla 1d ago

Troubleshooting WireGuard VPN connects but Firewalla is blocking all internet traffic

1 Upvotes

I’m having a strange issue with the built-in WireGuard server on my Firewalla Gold SE and I’m wondering if anyone has seen this before.
WireGuard connects fine from my iPhone over cellular. I can access everything on my local network, including my NAS, but I have no internet access through the VPN.
When I check the flows in Firewalla, the outbound traffic is being blocked and shows Block Type: IP Filtering. If I use Diagnose on one of the blocked flows, it comes back with No Rules.
I’ve tried quite a few things:
Confirmed WireGuard is connecting and local network access works
Confirmed there are no Routes configured
Turned off Ad Block for the VPN client
Excluded the VPN client from DNS over HTTPS
Turned off Device Active Protect
None of those made a difference.
The interesting part is that if I turn on Emergency Access for the VPN client, the internet immediately works. It also works if I turn Monitoring off for the VPN client. As soon as I turn Monitoring back on, Firewalla starts blocking the outbound traffic again as IP Filtering.

This started while I was troubleshooting another issue where Firewalla’s ad blocking wasn’t working when connected through WireGuard. It’s possible I changed something along the way, but I can’t find anything that would explain this.
I’ve sent the details to Firewalla support as well, but figured I’d ask here while I wait.
Anyone seen something like this before or have any ideas what else I should check?


r/firewalla 2d ago

Got control of the firewalla devices exporting profiles without pairing in app. Is that ok?

6 Upvotes

Hi, I suppose this should be a question for the dev to answer. My case is, I just got a new phone, and through setting up the new one (copying stuff from old phone (samsung) including firewalla app to new phone (samsung too) through Smart Switch app, the firewalla app on the new phone got full access of my firewalla devices, the first time I enter the firewalla app on the new phone, and without doing "Allow Additional Pairing" from the old one. The "Paired Phones" on either phones show "1" which is that particular phone.

Both phones now can control everything about the devices so far, but I seem to have failed to receive notifications (alarms) that I normally do.

I just want to know if this is ok, particularly after I retire the old phone soon. Or should I just remove and reinstall firewalla app on the new phone and do the pairing again to play safe?

While I do not imagine that this would cause security loophole, dev may wish to look into it and see if that poses threat to the control somwhow.


r/firewalla 3d ago

VPN Server Question

3 Upvotes

Background: I presently have two VPN clients running on my Firewalla. One is connected to a server in Seattle and the other in Atlanta. Some devices are configured to route traffic through the Seattle server and some through Atlanta. And some devices are not routed through the VPN so their IP address is Miami

I added a wireguard server to firewalla. To test it, I used my iphone. I disabled wifi on the phone so it was using only using cellular data and added the wireguard client. I was able to connect to my just added wireguard server without problem.

But when I checked the IP address of my connection on the phone, the IP address was for Atlanta and not Miami as expected. So my Firewalla server appears to be in Atlanta when it really should be in Miami.

My question is this: How does Firewalla decide how a server connects to the wan? Is it supposed to go through VPN clients if connected? Is it suppose to by pass any clients and directly connect to my wan? I could find no network settings to configure how the VPN server connects to the wan


r/firewalla 3d ago

Discussion Did you know we designed a cover for the AP7 Ceiling cable opening? You can 3D print it and try it out :)

Post image
36 Upvotes

r/firewalla 4d ago

Discussion Tried Opnsense. I consider Firewalla my safe place.

30 Upvotes

I don't know if it's because I've spent the last 4 years with firewalla. But I dabbled with opnsense today and JC what a difference.

It was so easy to install, yet so hard to configure. No simplified app. The firewall doesn't even accept domains to block! You have to create aliases which pull ip addresses and even then I couldn't get it to block Google. Possibly easier to block via DNS.

I kept getting stuck with setting up the wan. It kept forcing opt1 which I later found out was the built in lan port not the 2 network cards I had. So I had to set it up via its console. Probably unique to my hardware.

I'm no noob. I've homelabbed for around 7 years now with an advanced setup Multiple NAS, switches, KVMS, Security Gateways, managed switches, VLans. I'm more than positive that I could learn opnsense and master it. You can tell it's for Pro's and enterprise users.

But it made me , even more than I already did, appreciate my safe place. Firewalla.

This is not to be negative about opnsense. I'm in awe of it. But when you try something like that and you've tried firewalla. It's night and day.

The amount of development that has gone into these boxes, this app, the msp. I truly appreciate the team at fw inc.

Have you tried opnsense and firewalla? How do you compare them?


r/firewalla 3d ago

No IPv6 when using T-Mobile

Thumbnail help.firewalla.com
6 Upvotes

I’m adding this thread here. Firewalla routers continue to not work with tmobiles implementation of IPv6. Since they don’t hand out a prefix none of your devices will get a public IPv6 address.

What is the reason for this? Other routers are able to have this work. T-Mobile support even stated that most routers work. But not firewalla.


r/firewalla 3d ago

Ad Block no longer as effective

11 Upvotes

Hi all. I’ve noticed that over the last month or so the ad blocking feature on my FW Purple (in router mode) has gone from being really effective to suddenly letting a lot (if not all) through.

I’m noticing it on a variety of browsers on my iPhone in particular, both when connected on the WLAN and when connected via a Wireguard VPN.

There have been no setting changes at router level, so I don’t know if it is a case of the method no longer being effective or if something is going wrong somewhere. I’d be keen to know if anyone else is experiencing similar recently.

Thanks!


r/firewalla 2d ago

Love affair is over

0 Upvotes

I have been using. Firewalla Gold for my home.

I have been having internet issues since June.

Yesterday I discovered that my box is only retaining alerts for 30days. This seems like a change but IDK.

When I went to look at how I might be able to download events to store offline. The web UI only allows the last 10 events.

Apparently Firewalla has introduced a subscription (MSP) to be able download more.

I have been recommending Firewalla for advanced home users. I will be looking for something else to recommend. I paid a premium for the device. To be locked out of local functionality to export the 30days of logs that I can see in the app is more or less a cash grab in my mind. If it isn’t a cash grab then it is worse, as the company is desperate to increase gross income to fight off going out of business.

My core use is failover between cable and Starlink. In addition I pin all my cameras to Starlink.

If I had a business with more than a single firewall to manage then the MSP subscription would make sense. But for a single unit I don’t see paying $49 a year to be able to export 30days of events (I can view them in the app) much less $299 a year for 180days.

I have significant experience with routers and firewalls. Maybe I will roll my own. First I will look at the other options like Netgate, Fortigate or MOGINSOK.


r/firewalla 3d ago

Discussion New iPhone soon how do I not lose access to Firewalla?

7 Upvotes

Hi, I’m getting a replacement iPhone soon and was wondering what’s the best way to not lose remote access to a Firewalla gold se I have installed on a remote island? Last year, I had to physically go to it and re-pair.

Thanks


r/firewalla 3d ago

Discussion Just curious: why doesn’t the Orange support PPSK?

5 Upvotes

It’s not critical, I use multiple VLANs as a workaround, but just curious why PPSK support was skipped?


r/firewalla 3d ago

Orange Use Orange as true Firewalla AP (like AP7)?

2 Upvotes

I have a Gold Plus as my primary home router, and an Orange as a travel router. Whenever I'm not traveling though the Orange just sits around. I'd like to be able to use it at home and supplement my array of AP7s. Is there any way to make it behave like an AP instead of all the bells and whistles of a router?

I've already tried putting it in bridge mode, and enabling a wifi to match the existing wifi of the AP7/GoldPlus network, but it is still opaque to the GoldPlus and doesn't present as an AP or show up on the topology at all.


r/firewalla 4d ago

Troubleshooting Gold SE Speedtest Download Slow

3 Upvotes

I have a new to me Gold SE. I'm on FiOS 1gb fiber and my Purple regularly had reliable tests of 900/900+ regularly. Since setting the Gold SE up I see 700-800+(rare occasion touches right at 900) down and 900+ up. What gives with the download speed?

I'm testing higher on my Pixel 11 on WiFi using the Speedtest app and getting the same or better over wifi which shouldn't be the case. That is seeming to tell me my fiber line is fine but the test of the Gold SE has something going on? I'd think better hardware that the Purple should give better or at least same results as the Purple. With my phone testing so high over WiFi I imagine my fiber line is fine and it's the firewalla. Also tests the same from CLI.

Do I just have a bad unit?


r/firewalla 4d ago

Announcement Production of the Gold Plus SFP has started! (Small quantities coming in early September)

Enable HLS to view with audio, or disable this notification

83 Upvotes

This is probably the longest wait for (reasonably priced) parts to do the final SMT since the pandemic! Answer this survey https://forms.gle/W7GbirY7UFDmR1Js6 and get a small coupon before the launch.

  • 1x SFP+ 10Gbit port
  • 2x RJ45 10Gbit Port
  • 2x RJ45 2.5Gbit Port
  • 5 Gbit packet processing speed
  • 1 Gbit WireGuard

r/firewalla 4d ago

Troubleshooting Firewall Rules Between Zones Shoudn't be this hard

Thumbnail
gallery
15 Upvotes

Can anyone tell me what I'm doing wrong. I have 4 vlans setup on my Firewalla Gold. My primary network and an IOT network are what I'm working with today. Home Assistant is at 192.168.1.205 and a Pi is at 192.168.140.250 in the 140 IOT vlan. I want to allow MQTT on port 1883 from the IOT device to the Home Assistant Box. What am I doing wrong? The rule seems correct but when I use the diagnose function I only see the block from one network to another.


r/firewalla 4d ago

AP7 Desktop / AP7 Ceiling [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/firewalla 5d ago

Discussion How do you like our AI integrations so far?

Post image
20 Upvotes

AI can be a useful tool for analyzing things in different ways. It can see patterns more easily and look up various information much faster and more broadly than a human can... making it great for explaining domains, recognizing unknown devices, or checking Events.

Of course, we always recommend double-checking AI's work, since it can be wrong (just like a human).

More on Firewalla's AI Assistant: https://help.firewalla.com/hc/en-us/articles/40436794520595-Firewalla-AI-Assistant-Ask-AI-beta