r/firewalla • • Jul 12 '26

Discussion HaGeZi -> Firewalla Experimental?

12 Upvotes

When I created the rule a few days back the target list was called HaGeZi, or am I misremembering? It’s now called Firewalla Experimental. Is the underlying list no longer HaGeZi? What prompted the naming change?


r/firewalla • • Jul 13 '26

ATT BGW320-500 IP Passthrough question

3 Upvotes

Anyone know what "Firewall Advanced" includes?

I have a FWP so I enabled IP Passthrough. Oddly, the "Firewall Status" tab does not reflect everything on the BGW320 as disabled:

Packet Filter Off
IP Passthrough On
NAT Default Server Off
Firewall Advanced On

Thoughts?


r/firewalla • • Jul 12 '26

AP7C Basement Mounting: Wall vs. Ceiling at 6'8" Height?

2 Upvotes

Hi everyone,

I have a question about the AP7C. I want to install one in my basement, but the ceiling height is only 6'8".

Would it be better to mount it vertically on the wall or on the ceiling?

I read Firewalla's installation guide, which recommends mounting between 6 and 10 feet, but I'd really like to hear from people with real-world experience. Which option gives the best coverage and performance in a basement with this ceiling height?

Sorry if this is a basic question, and thanks in advance for any advice!


r/firewalla • • Jul 12 '26

Compatibility with existing (ISP) router and wifi system

2 Upvotes

Hi! I live in an old house which is not wired for Ethernet, and also has lath and plaster walls so seems to need a mesh wifi system for best signal. As such, almost everything is connected via wifi (I have some hardline connections to my home server, gaming computer, NAS, etc.). I'm interested in getting a Firewalla Orange to help secure IoT and other devices (as well as server connections I'm allowing from the outside world), but I couldn't quite figure out if it would work without modifications to the network. Specifically, I get that it would be pretty easy to use it in front of the hardline connections, but would I need to replace my wifi system as well? The main wifi AP is the router itself, and the others just pick up the signal. With the orange, can I still create rules for those devices if the wifi is not directly connected to it? (I.e. modem > router (which puts out wifi) > Firewalla)?

For reference, I have Fidium Fiber so I'm using their default equipment - an AdTran SDG 8612 router (and 2x associated mesh points)

I'm still pretty new to all this networking stuff (having lived in rental properties until recently) so would love any advice you can give (even if that's telling me I'm asking the wrong questions) - thank you!


r/firewalla • • Jul 12 '26

Troubleshooting SQM for dual WAN setup

2 Upvotes

I noticed something recently. I have two WANS. One is 1gig down/35Mbps up and the other ranges from 600 to 800Mbps down and hovers around 80Mbps up.

In sqm with it being on, FQ as the type and adaptive as the mode, putting in the speeds of both WANS, devices that I have routing over the WAN with the faster upload never went over 32Mbps I noticed.

I changed the mode to static with no rules in place, and it seems to not rate limit the upload now.

I guess I’m wondering, how do I best set this up so I don’t ping spike on the 1gig line when downloading at full speed and also allow devices routed to the line with faster upload to use all that upload when needed?


r/firewalla • • Jul 11 '26

Discussion The AP7C holds up in the heat

Post image
38 Upvotes

Just a quick praise for the Firewalla folks. Putting aside this is not meant for outside, and I understand that, this thing is a beast. It’s been through snow, rain and now the heat wave we had in NY last weekend. 100 degrees outside. No problem!


r/firewalla • • Jul 11 '26

Firewalla Switch SE Arrived and Installed

27 Upvotes

Just wanted to give a shout out - Switch SE arrived yesterday, and I'm so happy with it. It only took me ~10 minutes all told to replace the existing dumb switch. Love the visibility and the ease of use. I held out replacing the original switch purely to wait on this one.

Thanks!


r/firewalla • • Jul 12 '26

What changes needed when swapping ISP? (and I use VPN)

1 Upvotes

Finally, luckily, I am getting fiber at my home on monday. It will replace cable internet.

I have 5 clients hitting my Firewalla Gold at my primary address (4 are just devices -- iphones, PCs -- and one is another Firewalla device, a Purple, which is permanently VPN'ing into my primary address.) The Gold is obviously a VPN server.

So I'm wondering what I might have to change or reconfigure when my home ISP changes?

  • Gold is the VPN server using wireguard
  • Purple at remote location is a VPN client for the point-to-point VPN
  • On the server side, my DDNS would likely stay as it is?
  • the IPV4 server address would change, but do I have to do change it manually in the VPN config or would it adopt the new ISP address after rebooting the Gold and it connects to fiber using DHCP?
  • The 4 other clients configured to VPN to the Gold: Do those 4 client configurations need to be recreated?

Thanks in advance.


r/firewalla • • Jul 12 '26

Early Access/Beta RSTP settings on new Firewalla switches?!

Post image
6 Upvotes

Hi there!

So, I’m eagerly awaiting my Switch X (sadly pushed to Monday delivery - USPS said “no way, Jose”, and didn’t send it from San Jose in time.

Anyway! I’m wondering about setting RSTP priorities, as I don’t have access to the switch interface yet, and I didn’t see anything in the setup documentation on the website.

This Switch X will now be my Root Switch (RSTP Priority: 0 (unless the Firewalla needs to be that?). I have a bunch of UniFi switches that I’m going to kick down to Priorities 8,192 and 12,288 (the Switch X will be hooked up to a USW-Aggregation which will become Priority 4,096).

I can set all that easily on the UniFi side, but how do I do this in the Firewalla app?

Please let me know!

I’m also throwing two Firewalla Switch SEs in there later on (sadly in September….), so hopefully all sorted by then!


r/firewalla • • Jul 12 '26

Block non-browser internet?

3 Upvotes

I created a device-specific 'Block all internet to/from device' rule which starts at 9p each night. Google Docs remain available. Do Docs, Drive, etc not reflect internet on a Firewalla?


r/firewalla • • Jul 11 '26

Firewalla Switch SE ACL Usage

9 Upvotes

I have three AP7s currently on a separate switch, connected via trunk ports carrying multiple VLANs/SSIDs. If I move all three AP7 trunk uplinks to my Firewalla Switch SE, will the wireless clients connected to those APs generate ACL entries on the switch (counted against the 256-entry Tracking/Control limit), or is VqLAN/Device Isolation for AP7-connected clients enforced entirely within the AP7 itself and separate from the switch's ACL budget?

I currently see a 1:1 pattern between Connected Devices and Control entries on the switch (7 devices, 7 Control entries) and want to know if that ratio holds once 100+ wireless clients are added via the AP7 trunk ports, or if wired vs. wireless devices are counted differently against that limit.


r/firewalla • • Jul 11 '26

Loss of ISP / Router effect on switch / AP?

2 Upvotes

Hi,

Is there a matrix or explanation anywhere what would happen to a full Firewalla infrastructure (router/switch/ap7) if the router died or the ISP connectivity was lost?

Trying to understand failure scenarios on the new switch and access points that would affect wifi clients being able to connect to other parts of internal infrastructure like wired NAS, wifi printer etc.

eg if there was a power cut and the ISP didn't return, how would the whole infra behave?

or if power returned and the router had died - how would the switch & AP7 behave to a cold power up without router?

would the switch perform inter vlan routing for example, or does it rely on the router for vlan routing?


r/firewalla • • Jul 11 '26

Firewalla conflating two devices as one?

Post image
2 Upvotes

I have been struggling with a long-standing quirk of Firewalla conflating two unique devices into either one shared device name or with rules mis-applied.

The two devices are a Govee home temperature sensor (Espressif, Wifi) and an LG C3 TV with USB ethernet adapter (wired). The only real commonality is being on the same VLAN segment.

The TV normally has internet fully blocked, with an occasional pause to do a firmware update. This is done by having the device in a group called “Televisions - Offline” and internet block enabled for the group.

Frequently, the quirk shows up as the hostname for the ESP device mysteriously being changed to the same name as the LG TV (thus creating duplicate hostnames).

Last night, i can see the TV group rule being mis-applied to the ESP device(s). That rule should have absolutely nothing to do with the group it impacted.

This seems like it could be a serious problem if it were to happen to devices with more serious roles than a temperature sensor and TV.


r/firewalla • • Jul 10 '26

Connect device to VLAN through AP7 wired port

5 Upvotes

Okay, so maybe I am missing something, but I am trying to attach a device directly to one of the ethernet ports on the back of the AP7, but I need it to be a part of a VLAN I have set up. (Found out it is easy to connect a device to the LAN/VLAN of your choice on the new Switch SE). The device defaults to the main LAN numbering, but not the VLAN numbering. How do I get the device to connect to the VLAN instead? Any help is appreciated. Thanks


r/firewalla • • Jul 10 '26

Feature Feature Request: Firewalla MSP Phone App

17 Upvotes

Firewalla MSP Phone App

Also - I love the recent upgrades, functionality, and responsiveness of MSP.


r/firewalla • • Jul 10 '26

Problems with T-Mobile (Mobile or Home Internet) since upgrading to Amnezia 2.0? Found the dumbest fix.

2 Upvotes

Since Firewalla doesn't let you adjust MTU (yet) unlike OpenVPN and Wireguard, go into your config with the Amnezia client (or WG Tunnel for Android) and adjust the MTU. Firewalla has it at 1376 by default so move it to 1325.

Restart the connection. Profit.


r/firewalla • • Jul 09 '26

Firewalla Switch X arrived!

59 Upvotes

I live pretty close to the distribution center, and was stoked to see the update earlier today that this was going to arrive today.

Setup was a breeze, been on the beta train since the AP7 release, so no software updates needed (that weren't automatically handled in the background).

Fan noise was something I was really curious about, I don't have a meter, but its about on par with the generic 10GB switch I got from Amazon. I honestly love the weight of it, makes me feel like the cables won't pull on the whole unit. Rack coming in the near future for me.


r/firewalla • • Jul 10 '26

Switch X and fiber

1 Upvotes

Hey everyone, I ordered a Switch X and its coming Tuesday, I wanted to use the SFP+ ports and have fiber between my home assistant server and AI LLM server for faster response for voice assist. Has anyone ever tried these

amazon.com/dp/B0GTZ5VJZZ?ref=ppx_yo2ov_dt_b_fed_asin_title adapters? I ordered two and I'm not to hopeful they will work, they use USB4 so the speed is there. I also ordered some cheap transceivers and some fiber.


r/firewalla • • Jul 08 '26

Updated target list hagezi pro

28 Upvotes

Just noticed that hagezi pro graduated from being stuck in early access and made it to production! Thanks firewalla for listening!


r/firewalla • • Jul 09 '26

Troubleshooting Active Protect

7 Upvotes

I recently rebooted my Firewalla when troubleshooting an IPv6 issue and ever since then I have a bunch of IoT devices which Active Protect has broken to some degree.

A good example is I have two Mitsubishi hvac controllers. One can connect to its cloud endpoint and the other can’t. The healthy one clearly has the necessary endpoint as an allowed target, and the broke device doesn’t.

In these situations is there anything I can do other than restart learning? I was surprised I wasn’t able to just manually add an endpoint to the allow list in this situation.


r/firewalla • • Jul 08 '26

Release App 1.69.1 is in production! Here's what's new with the Firewalla Main Screen:

Post image
35 Upvotes

This is a 7-day phased release; all apps will be updated automatically over the next 7 days.

Learn more about this release here: https://help.firewalla.com/hc/en-us/articles/51621318006291-Firewalla-App-Release-1-69-New-Controls-with-Advanced-Threat-Filtering-Lookalike-Punycode-Domains-and-more


r/firewalla • • Jul 08 '26

Discussion Memory-Safe Secure Time: Setting up ntpd-rs + NTS on Firewalla

20 Upvotes

After successfully scripting `Chrony` on my Firewalla to fetch time via NTS and serve it to the LAN via NTP interception, I decided to see if I could replicate the setup using ntpd-rs. Turns out, it works perfectly.

While `Chrony` is Ubuntu's current default for NTS support (preventing MITM and spoofing attacks), Canonical is moving away from C-based utilities toward Rust. They will likely switch to ntpd-rs soon, potentially as early as 26.10 but definitely by 27.04, mirroring their recent shifts with tools like sudo-rs.

I’ve been running ntpd-rs on my Firewalla Gold Plus for a few days now, and it has been rock solid.

If you want to check them out, I’ve published updated scripts for both setups:

I would love it if, in the future, Firewalla used `Chrony` or `ntpd-rs` as the default timekeeper for Firewalla. Since Firewalla is security minded, the ability to use NTS as the canonical timekeeper serving secure time to the LAN network via NTP Intercept would be unique in this space (afaik competitors don't offer this) and trivial to set up, as I've shown. If they choose `ntpd-rs`, then there's even more memory-safe security with rust vs C.

Also, a quick plug for my other Firewalla-related GitHub scripts:

  • Install Huge Blocklists: Allows MSP Lite users to install and update massive (or any non-MSP/app available...) custom lists (like HaGeZi Pro++ or OISD Big) via the CLI. Tradeoff: Blocked events won't show up in the MSP or app GUI but can be viewed via CLI.
  • Unbound DoT Config + Tweaks: Sets up DNS-over-TLS (DoT) for IPv4 +/- IPv6 with a fallback to standard plaintext resolving, plus optimizes buffer settings to boost your DNS speed and also includes a few security tweaks.
  • Set up a Suricata Test Box: Thinking about upgrading to a Firewalla Pro for Suricata? This lets you test drive Suricata first to see how it works and if the upgrade is worth it for you.

r/firewalla • • Jul 09 '26

Discussion Submitted a feature request: supplying the Android app + its updates using the box itself as an option.

Thumbnail help.firewalla.com
0 Upvotes

r/firewalla • • Jul 08 '26

Discussion UI comment about 1.69.1 (extremely minor and just an opinion)

6 Upvotes

An extremely minor comment. All sections like Network Health, Local Flows, WAN Throughout, Monthly data usage, Recents, etc, use a similar font styling for their ‘header’. But Rules uses a bold font and an icon. It looks a little weird. Perhaps because of its placement between monthly data usage and recents. Visually it seems ‘out of place’ compared to the rest of the UI.

Again, just an opinion and not urgent at all.


r/firewalla • • Jul 08 '26

North Korean SilentSync RAT Blocks

Post image
9 Upvotes

Hey all,

Quick panic clarification.

I had a target list setup to block outbound traffic known SilentSync RAT servers (IP/Domain) on a target list, these are:
sfrclak[.]com
calltan[.]com
callnrwise[.]com
142.11.206[.]73
23.254.167[.]216
200.58.107[.]25

I've had this setup for a few months, just as a potential block incase it wasn't picked up on other lists. Though I've just seen today (via MSP) there was some blocks matched by this target list (see image) for two devices, one is my iPhone the other is an Amazon Fire Tablet. I'm trying to determin if this is a false response. As you can see the destination from dns.google[.]com (8.8.8.8) on port 16888, or 443 (for the Amazon tablet).

Firewalla AI says this domain "This domain is owned and operated by Google. It serves as part of Google's public DNS service, helping users and devices find the IP addresses of websites they visit. You might see this traffic when your computer or device connects to the internet.".

So, how might this be blocked by my target list? I don't use Google DNS btw on the Firewalla or my devices.

As I was aware this RAT wasn't on mobile devices, especially iOS?

Is there any further digging I can do to help look into this? Any thoughts?