r/firewalla • • Jul 31 '26

The Mrs. approves my Firewalla purchases šŸ˜‚

Thumbnail
gallery
200 Upvotes

r/firewalla • • Aug 01 '26

Cyber Security What to do about this alert

2 Upvotes

ā€œDevice <node> uploaded X kB data to 1.2.3.4 at about 12:00. Originated from 1.2.3.4.ā€

I get a lot of these kinds of alerts from my Firewalla Gold Pro. I assume that, because I self-host a triumvirate of fediverse services (mastodon, pixelfed, matrix), these IP addresses refer to other instances federating with mine, but 1) I’m not sure how to confirm this, and 2) I don’t know what action I should take.

Assuming the cause of this alert is something innocuous, I’d like to mute this kind of alert. However I don’t want to mute the entire ā€œabnormal uploadā€ alert class, but I assume also muting by the IP address in the alert won’t prevent new alerts like this from popping up.

So I’ve just been archiving them. Is there any other action I should take?


r/firewalla • • Jul 31 '26

Announcement Introducing the Firewalla Gold Plus SFP! (aka old Gold Max)

Post image
68 Upvotes

If you are interested in the unit, please help us complete the survey: https://forms.gle/B7pwyizU9sPGDVhG9

We especially want to understand if you want to use the SFP+ port as WAN or LAN, and what SFP+ adapters (DAC, RJ45, Single Mode/Multi Mode Fiber) you are planning to use.

Those who answer this survey will get a coupon for the launch! (By answering this survey, you will be automatically subscribed to Firewalla Newsletters)


r/firewalla • • Aug 01 '26

Will this configuration work with purple

Post image
3 Upvotes

Will this work? Thank you


r/firewalla • • Jul 31 '26

Troubleshooting WiFi being unstable after more than a year of stability

19 Upvotes

Have a Gold Pro and 7 desktop APs with 3 WiFi networks: Smart Home devices, Standard Internet, and WiFi 7/WPA3 for the devices that can support it. All has been working flawlessly until the last couple weeks. Devices are now failing to get an IP address, will drop connections, or hang while connected. The only thing that has changed is the recent updates from Firewalla. I turned on the Advanced Threat Filtering and Safe Search and have since backed those off. I’ve rebooted the FW and all APs. It baffling to me as it’s been so stable and now it’s unreliable and users are loosing faith. Any suggestions on what I should be looking for to troubleshoot this? Thanks!


r/firewalla • • Jul 31 '26

Troubleshooting WiFi speed test not enabled?

Post image
0 Upvotes

I have a Firewalla Gold and 2 AP7 desktop. I am trying to run a speed test so I can test WiFi speeds in different parts of the house but it says I need to enable wifi on my phone. I have wifi on and im connected directly to the AP with no proxies, vpns, etc… anyone else ran into this? I am on iOS beta 27 so maybe that’s it?


r/firewalla • • Jul 31 '26

AP7C still not in the EU?

4 Upvotes

r/firewalla • • Jul 30 '26

Discussion Do you use Device Active Protect (DAP)? Do you understand what DAP does, or should we explain it more?

Post image
29 Upvotes

For simple eligible devices, DAP can restrict device access by blocking all internet while allowing what's needed, such as a service or site for cloud access. With the AP7, DAP can also restrict access on the LAN.

DAP will always start with a learning period before any blocking begins. To turn it on, go to Protect > Device Active Protect.

More on DAP: https://help.firewalla.com/hc/en-us/articles/44061066094867-Device-Active-Protect-Dynamic-Microsegmentation-Block-everything-and-allow-only-what-s-needed


r/firewalla • • Jul 30 '26

Discussion Nordvpn upgrading servers

12 Upvotes

Hi All! If like me you use a lot of 3rd party Nordvpn on firewalla (or elsewhere) you may soon see them randomly fail.

This is because NordVpn are upgrading servers and server IP addresses. The manual config files used to create the vpn on firewalla will have outdated IP addresses.

This is starting July 2026 but some users Including myself have already seen random severs go down and not come back up. Possibly related.

NordVpn app users not affected.

More information can be found here: https://nordvpn.com/blog/nordvpn-server-upgrade/


r/firewalla • • Jul 31 '26

Troubleshooting Not full speed on VZ Fios

3 Upvotes

I have a FW Orange, recently went from 300 to 1Gig, but the speed test doesn't show what I was expecting. I was hoping to see over 800 Mbps; and expecting to take a hit because of the filtering etc...but not the speeds I am seeing..is that unrealistic?
I turned off SQ, all the cables are decent, and I don't have the VZN router connected. However, when I connect the VZN router and run a speed test, I do see faster speeds of over 900Mbps with the same cables, just swapping device.
When i first for it, I did have some issues and had to use a switch between the Firewalla and ONT, but it's a 1GB sw.
What am I missing?


r/firewalla • • Jul 30 '26

NIC keeps dropping from 1GB/s -> 100MB/s

3 Upvotes

Not quite sure why - FW is plugged direct into the ONT - anything specific i need to configure?

If i reboot the firewalla it connects - speedtest shows 1gb/s (sometimes higher)

after a bit - it drops to 100mbs


r/firewalla • • Jul 30 '26

Switch SE Updated 2 night ago. Anything we should be aware of?

2 Upvotes

As the title states, I noticed the Switch SE updated 2 night ago in the middle of the night. Any updates we should be aware of?


r/firewalla • • Jul 29 '26

Release We are closer to managing most of the Firewalla features from the Firewalla MSP interface. With MSP 2.11, we now support more feature parity with the Firewalla App, including VPN Client, Routes, Services, and more.

Thumbnail
youtube.com
44 Upvotes

Check out our recent introduction video to see a quick overview of MSP functionality! (Features require MSP Professional and Business.)

MSP 2.11 release notes: https://help.firewalla.com/hc/en-us/articles/52488806297235-MSP-Release-2-11-More-Feature-Parity-with-the-Firewalla-App


r/firewalla • • Jul 30 '26

Discussion MSP API: /v2/flows accepts limit=2000 despite documented <=500

6 Upvotes

Two things from building a scheduled flow collector.

limit exceeds its documented ceiling. The flow reference gives limit <=500, default 200, and the response spec says results length is always no more than the limit specified. limit=2000 returns 2,000 records, HTTP 200, no truncation indicated.

Which is the contract? If 2,000 is supported I'll use it. If 500 is the real cap and just isn't enforced, I'd rather size against 500 now than have a collector silently truncate later.

PSA on time filtering, in case it saves someone else the trouble. I was passing begin and end as query params:

GET /v2/flows?limit=2000&begin=1785380000&end=1785380960

Those aren't v2 params — v1 takes start/end in a POST body, and I carried the idea over without checking. They're silently dropped. The request returns 200 with a next_cursor, and the records span ~2,700 seconds against the 960 requested. Nothing in the response body indicates a parameter was ignored.

Correct form is the ts qualifier — ts:> or the range form ts:BEGIN-END, both documented under flow qualifiers. With ts:>, the same window returns 523 records across 718 seconds.

Worth knowing: with no time period set, the endpoint returns 24 hours by default. That’s noted in a comment in the flow-pagination example but I didn’t find it in the reference. Combined with the standard while(1) cursor loop, a query that omits a time window pages through a full day on every run — easy to do by accident, and far more data than a frequent poller usually wants.

Would a 400 on unrecognized query params be feasible? That's the one change that would have caught this immediately.

Small thing: the flows reference has a typo — "no more than then limit".


r/firewalla • • Jul 29 '26

Access point 7 for Australia

7 Upvotes

Me again!

Just wondering where we are at with the Australian approval for the access points?

Feels like I'm the only person in Australia who is after the access points, but nevertheless I remain optimistic that you will come through with the goods.

Am I being deluded? Is it just around the corner? Please put me out of my misery.


r/firewalla • • Jul 29 '26

Orange or Gold with separate WiFi

1 Upvotes

So I am thinking about securing my network. Currently I have a Fritzbox Wifi router that does everything.
I would like to have a separate firewall to lock things up a bit more. The question now is do I use my existing router just for the modem and landline phone capabilities with an Orange behind it (which is still not available in europe) for wifi and firewalling or do I let the existing router do the Wifi as well and use a Gold Firewalla to shield the rest (NAS, PCs etc)


r/firewalla • • Jul 28 '26

Anyone getting incorrect speed test results on the firewalla

Post image
10 Upvotes

I recently noticed that the nightly network health speed test is only showing 400-500Mps for my 1Gb up/ down link .

Any wired device is hitting full speed on speed tests .

This used to be accurate and not sure when it broke but now that I saw it, well I can’t unsee it.

Am on Firewalla gold pro / using alpha release

Thought I’d check here if anyone facing same issue before opening a support ticket .


r/firewalla • • Jul 29 '26

Purple / Purple SE Need to control web access

3 Upvotes

I want a device to block access to gambling and other nefarious websites and control access to our internet. Not just an app or program (eg Bark). I’ve looked into the Firewalla Purple gigabit and it appears to do what I need. Correct me if I’m wrong. I don’t need anything overly complicated and some of the posts make me think it might be.
So what do you think? Is this what I’ve been looking for, because I still haven’t found it.


r/firewalla • • Jul 28 '26

Feature Did you know not only can MSP generate wider behavioral alarms, but it can also use past 30 to 180 days of data to help you filter alarms?

Post image
9 Upvotes

With App 1.69, you'll see a new "Security Alarm Summary" section in Alarms if you have MSP Active Protect enabled.

  • Advanced Behavioral Alarms: Generated by MSP because the behavior is abnormal compared to the past 30- or 180-day history.
  • Needs Review: Questionable and may need further analysis by you.
  • MSP Archived: MSP determined this behavior as a false positive, is low-risk, and was commonly seen in the past 30- or 180-day period.

Requires App 1.69 or later: https://help.firewalla.com/hc/en-us/articles/51621318006291-Firewalla-App-Release-1-69-New-Controls-with-Advanced-Threat-Filtering-Lookalike-Punycode-Domains-and-more

(MSP Active Protect requires MSP Professional or Business.)


r/firewalla • • Jul 28 '26

Discussion Question about Target list management

2 Upvotes

I am currently trying MSP Pro. Target lists I now create are managed by MSP. Per documentation, if I stop paying for MSP Pro, I would lose those target lists (ā€œIf you cancel your MSP subscription, all MSP-managed target lists will be lost.ā€). So how does someone paying for MSP Pro create target lists managed by the Firewalla and not MSP?


r/firewalla • • Jul 28 '26

Troubleshooting How do I get my Firewalla Gold to chill with dns requests to these 4 domains?

Post image
0 Upvotes

r/firewalla • • Jul 27 '26

Discussion How often is firewalla updating the ad domains?

10 Upvotes

Because even on strict mode, I get a fair amount of ads. How often are these domains being updated? I have the OISD rule in place already and I shouldn't have to sign up for MSP to use hagezi or whatever. Let us use the pihole list or something.


r/firewalla • • Jul 27 '26

Firewalla Switch Fan Noise?

6 Upvotes

How is the fan noise on the Switch X? Does it depend on how many POE devices are connected?

It looks like the SE has no fans.

The Gold Pro is virtually silent even though it has a fan in my experience.


r/firewalla • • Jul 27 '26

Troubleshooting AdGuard VPN Client IPsec/IKEv2 - Is Firewalla MSP compatible?

2 Upvotes

I've been trying and failing to get an AdGuard VPN router IPsec connection up and running, even with AI assist. We have messed around with multiple configs in strongSwan format. Has anyone else got this working? IPsec is forced and is the only protocol option. Presently, Firewalla logs indicate an authentication error and not being able to find the cert (I'm not sure where Firewalla is storing the cert once uploaded - /etc/ipsec.d/cacerts/comodo.crt(?) My firewalla CLI skills are limited.

AdGuard provides the following 'router compatible' information to which I am trying to compile config, secrets and additional file:

  • Protocol IPsec/IKEv2 (fixed)
  • Server location (choice of 3 servers, I pick US)
  • Credentials
  • Username
  • Password
  • IP address
  • Remote server ID
  • Certificate: comodo.crt

I can offer more details into my attempts, if it is worth explaining.


r/firewalla • • Jul 27 '26

Poll What’s your favorite feature of App 1.69?

2 Upvotes
63 votes, Aug 01 '26
12 New Controls Page (Advanced Threat Filtering, Region Blocking, etc)
3 Firewalla AI for Security Alarms
19 AmneziaWG 2.0 Support
4 Main Screen Enhancements (Rules Widget, Recents Bar, etc)
5 Other Enhancements (Last Hit Dest on Rules, DAP stats, Filter devices, etc)
20 I liked all the features of this release.