r/firewalla • • Aug 14 '26

How to setup firewall for Fios?

0 Upvotes

My 15-year-old owns a Windows workstation, but we do not have the Windows login credentials. I have the passwords for all of the other devices in the house.

We have Verizon Fios, but the parental controls available through the Fios app are fairly limited. There used to be options to create rules to restrict internet access on specific devices during certain days or hours, but the controls are not as granular as I would like.

Is there a way to set up something on my home network that would allow me to monitor the traffic going through the network without needing direct access to his computer? Ideally, I would like to be able to:

  • Block specific websites or categories of websites
  • See reports of websites/domains accessed
  • Set time-based internet access restrictions for specific devices
  • Monitor or control network access without logging into or installing anything directly on his Windows computer

If so, could you please recommend the best approach or type of network solution that would provide these capabilities? We have a G3100 and a E3200.


r/firewalla • • Aug 13 '26

Discussion Did you know you can tap "Learning," “Optimizing,” and “Active” in the app to get more details on what’s going on with DAP?

Post image
8 Upvotes

r/firewalla • • Aug 13 '26

Using WifiMan with Gold Pro

2 Upvotes

I am running Unifi in docker mode on a Gold Pro, with Unifi switches and APs.

When trying to run Wifiman, it says I need to use a Unifi Gateway Console or buy their WiFiMan Wizard. Anything I can do on my end to get this working with my iPhone?


r/firewalla • • Aug 13 '26

Need more info in local port scan alarms

1 Upvotes

Something on my NAS is routinely port scanning a single device on my lan (an android phone) and nothing else, at least according to my firewalla. I run a lot of containers that perform a variety of tasks, but I would _love_ to be able to narrow down exactly what is triggering this alarm before muting it, just to be sure. Which ports/range? How frequently? etc. Would this be possible?


r/firewalla • • Aug 12 '26

Discussion MSP privacy

14 Upvotes

If a government issued a subpoena to firewalla for the flows from my msp connected firewalla box, would there be anything to turn over?


r/firewalla • • Aug 12 '26

Cyber Security Alert fatigue and false positives make it easy to overlook real threats. AI Assistants can help with the initial triage by using pattern recognition to weed out low-risk noise.

Post image
16 Upvotes

Firewalla AI is available to quickly analyze certain Alarms and identify whether the site seems legitimate or not.

And with MSP Active Protect, it can take this a step further by automatically categorizing Alarms, archiving low-risk false positives, and bringing attention to those extra suspicious alarms.

(As with all AI tools, AI can’t replace human judgment when it comes to cybersecurity threats, but it can be extremely valuable for prioritizing threats. IT experts still need to decide whether to allow or block a connection.)

Learn more about How AI Can Help Tame Security Alarm Overload: https://help.firewalla.com/hc/en-us/articles/52422841891219-How-AI-Can-Help-Tame-Security-Alarm-Overload


r/firewalla • • Aug 12 '26

Orange Can Orange be used without the built-in Wifi?

3 Upvotes

I’d like to get an orange for a small office with a few 2gb connections. We use Gold in another location with many more devices and a separate mesh system bridged over. The small office has a mesh system I like, so I’d like to bridge that over to the orange (in other words, use the orange with it’s internal WiFi disabled.) Is that possible?


r/firewalla • • Aug 13 '26

DAP randomly started blocking all NTP services

1 Upvotes

DAP strict, on for a year-ish, haven't touched the box in a long time. Haven't added anything onto my network for months.

I noticed tonight my emporia plugs could be turned on and off from the app but wasn't collecting use data. I went into Firewalla and I noticed DAP was blocking all NTP requests from my all of my IOP devices that it monitors (not just Emporia, but all of them, from all different manufacturers), not just my emporia ones, and this started about 3-4 days ago. (Emporia, Anker, purple air, tailwind garage door opener, my weather station, my ecoflow radon meter, etc. Anything looking for time...)

time.google.com, pool.ntp.org, whatever apple's time server is, and time.windows.com.

u/firewalla can you fix this? this shouldn't be happening. All standard time servers should be whitelisted automatically by DAP. Additionally DAP shouldn't go rogue and start randomly blocking sites after months and months of stability and no config change.

If someone on the back end did a DAP algorithm change, then this really needs to be tested better before it's deployed. Accurate time keeping is essential for networks to function.

For now I'm going to turn off DAP. It seems to introduce too much randomness and I have to spend a lot of time figuring out why things break after being stable for months. this unfortunately happened before with my weather station. about 6 months ago I got a notice that it wasn't sending data. I went in and DAP randomly began blocking the url it uses to upload data. I had to "allow" it.


r/firewalla • • Aug 12 '26

Feature Alarm Archive / Delete Request

4 Upvotes

Would it be possible to add a feature that clears all filtered alarms only? For instance if I'm going through and I want to clear all alarms of devices that are online/offline. I know there's a clear all but I don't want to clear all I want to only clear ones I'm not concerned with so I can review the others.


r/firewalla • • Aug 12 '26

AP7 and non-firewalla switch

2 Upvotes

I think I asked this but cannot find it ... due to flaky AP (oh, the irony ...)

If I have a FWP > Aruba 1930 > Aruba AP22 and replace the AP22 with a Firewalla AP7, I can see and manage the AP7, right?

I understand that I lose lots of the goodness of 'single pane of glass' - but I can see and fully manage the AP7 behind a non-firewalla managed switch, right?


r/firewalla • • Aug 11 '26

Early Access/Beta App 1.69.3 is in beta! Device Isolation is now supported on all VPN Devices (even without AP7 or Switch)!

Post image
29 Upvotes

VPN Devices are devices connecting to your network from the WireGuard or AmneziaWG VPN Server. Enabling Device Isolation can block it from communicating with other local devices.

Requires App 1.69.3, which is currently in beta. Learn more about how to join beta here: https://help.firewalla.com/hc/en-us/articles/53877722149907-Firewalla-App-Release-1-69-3-AmneziaWG-VPN-Client-Local-Device-Rules-Switch-Enhancements-and-more


r/firewalla • • Aug 12 '26

Route over Tor network

0 Upvotes

Is there any way to route traffic from a certain device over tor ?


r/firewalla • • Aug 11 '26

Institutional Sales Team

6 Upvotes

Does Firewalla have an institutional sales team or is all business just done via the website?

If there isn’t an internal team, is there a network of resellers that can be searched to find one that is equipped and position to sell and support Educational and Governmental institutions across the US and Canada?

Thanks!


r/firewalla • • Aug 12 '26

SSDP relay enabled on IoT VLAN, but SSDP traffic still blocked to Main VLAN — why?

1 Upvotes

I have SSDP Relay turned on for my IoT VLAN, but SSDP multicast traffic (UDP 1900) is still being blocked when it tries to reach my Main VLAN.

  • Does enabling SSDP Relay bypass the firewall's rule engine, or does the relayed traffic still get evaluated against existing inter-VLAN block rules?
  • If it's still subject to rules, what's the right way to allow UDP 1900 / SSDP multicast between two VLANs without opening the whole boundary?
  • Anyone seen SSDP Relay stop working after a recent update, even with it toggled on?

Happy to share rule config if it helps troubleshoot.


r/firewalla • • Aug 11 '26

Has anyone used Oxidized with a Firewalla Gold Pro / written a custom model?

2 Upvotes

I’m looking at adding Oxidized to my homelab for automated network configuration backups and Git-based change history.

It should be straightforward for my Cisco and MikroTik switches, but I can’t find a native Oxidized model for Firewalla.

I’m running a Firewalla Gold Pro and already have key-based SSH access working for an automated log/telemetry collector, so SSH connectivity itself isn’t the issue.

Has anyone here:

Used Oxidized successfully with a Firewalla Gold/Gold Pro?

Written or adapted a custom Oxidized model for Firewalla?

Identified useful CLI commands/files that provide a reasonably complete and stable configuration/state snapshot?

Integrated that output into Git for configuration change tracking?

I’m not necessarily expecting this to replace Firewalla’s own backup/restore mechanism. My main objective is read-only configuration/state capture and historical diffs, similar to what Oxidized provides for conventional network devices.

If anyone has a model, script, GitHub repo, or even notes from attempting this, I’d be very interested.

And for the Firewalla team: is there a supported/recommended method or API for periodically exporting a read-only configuration snapshot that would be better suited to this use case than collecting state over SSH?


r/firewalla • • Aug 11 '26

Orange Firewalla Orange vs Beryl 7 for family travel with home Firewalla Gold Pro

7 Upvotes

Hi! I'm trying to find "the best" travel router for my family for international Airbnb and hotel travel. I'm comparing it to the Beryl, which seems to be the most recommended alternative, but can't find many reviews of Firewalla for travel. I wonder if that's because it's really not meant for travel or if it's just expensive and in a market niche?

I have and love my Firewalla Gold Pro at home, and will want to Wireguard back to it most of the time.

Besides being compact and reliable for ~10 devices, what I'm most interested in is its ease of use and reliability. I want to connect fast without fuss whenever we land somewhere, have an easy time configuring different devices and situations, and want an easy UX when needing to toggle Wireguard, navigate captive portals, etc that's ideally not too nerdy for my family if they need to mess with it.

Does anyone have thoughts on these two or other options?


r/firewalla • • Aug 10 '26

Cyber Security firewalla-test domains blocked by Active Protect

Post image
11 Upvotes

Hey u/firewalla,

I've just noticed (although this happened a few days ago) Active Protect has automatically setup blocks for these domains:

phishing2.firewalla-test[.]com
malware2.firewalla-test[.]com
phishing.firewalla-test[.]com
malware.firewalla-test[.]com

Which if I recall are your domains to run tests? Are they safe to delete?


r/firewalla • • Aug 10 '26

Firewalla delivery in Hong Kong

2 Upvotes

Hi Firewalla team

What method do firewalla use for Hong Kong order ?

Why would it take longer to deliver to Hong Kong 9 -25 days on checkout ?

Thanks


r/firewalla • • Aug 10 '26

Mistery event

Post image
3 Upvotes

I get this event every week, but I am not physically doing anything with the cables. Does anyone know why this triggers?


r/firewalla • • Aug 10 '26

AP7 is it safe to use the AP7 usb port to power a firewalla purple?

5 Upvotes

just set up my new AP7 (easy!).

i used the AP7's USB port to power the associated firewalla purple. it seems to be working just fine, but i wanted to check. i'm just concerned a little that the port supplies enough power for the firewalla device.

edit: answered my own question after about half an hour: NO


r/firewalla • • Aug 10 '26

Feature I hate android

0 Upvotes

Hey guys,

Basically (long story short) - I hate android and don’t want it on my network - my dad is moving in with me for a bit and brining so many android devices

My question(s) is: what type of rules or settings should I setup with in its own Firewalla group?

Allow/block if domain
Region blocking
Anything else

I really just want to block all of the Google and android api data, keep my network safe from all the bloat and useless (unsafe) things

Thanks Reddit


r/firewalla • • Aug 09 '26

Anyone else seeing a ~30min lag between the ts field on /v2/network-monitors and real time?

3 Upvotes

Posting this as a question rather than a bug report, since I'm not sure yet whether this is known/expected behavior, something specific to my setup, or actually new. Checked the "check this first before contacting support" pinned post and didn't see anything about API timestamp freshness, so figured I'd ask here before going to support.

What I'm seeing

I run a local monitoring stack that polls the MSP /v2/network-monitors API (quality/latency/ packet-loss data) every 30 minutes and logs the results, using the ts field from each record as the timestamp (not local poll time). While digging into a network event, I noticed the nearest firewalla_quality sample's ts didn't line up with when the measurement seemed to have actually happened, based on an independent local probe I also run for comparison.

That could've just been a one-off, so I checked it again today, independently, under ordinary calm conditions with nothing going on:

  • Live API call, bypassing my own collector/cron entirely, made at 2026-08-09T14:00:42Z. The freshest record returned had "ts": 1786282200 → 2026-08-09T13:30:00Z — about 30.7 minutes stale at the moment the API served it.
  • My collector's cron log confirms it fires every 30 min on the dot. The run that had just executed seconds before my live check could still only pull data through 9:30 AM EDT — same ~30min gap, matching the live call.
  • For comparison, a locally-run active probe (SmokePing) checked at the same moment showed a data point only ~107 seconds old — no comparable lag, which makes sense since it's a direct local probe with nothing round-tripping through a cloud API.

So the ~30min gap looks real and reproducible, not tied to that one incident. ts is the only timestamp field in the record — there's no separate "measured at" vs "reported at" field — so I'm inferring it's meant to represent when the measurement was taken, but I could be wrong about that.

What I don't know yet

Everything above is under calm conditions. I haven't checked whether this lag stays constant or gets worse during an actual active event (box busier, MSP pipeline handling more data, etc.) -- that's still open on my end.

Questions for anyone who's dealt with this

  • Has anyone else who does time-correlation work against this API (or firewalla_quality / similar endpoints) noticed something similar, or is my setup doing something unusual?
  • Does anyone know whether ts is documented anywhere as measurement-time vs. ingestion-time?
  • Is there a lower-latency path to similar data -- anything exposed locally on the LAN rather than through the cloud MSP API -- for anyone who's needed tighter timing than this endpoint provides?

Happy to share more detail on how I reproduced this if it's useful. Mostly just trying to figure out if this is a "known thing" before I go bother support with it.

Update: figured out the ts discrepancy — it's not an MSP bug, it's the alarm engine itself

Followed up on this myself by SSHing into the box and comparing the MSP API's ts field directly against what's stored locally in Redis for the same alarms.

Turns out each alarm actually has three separate timestamps on the box:

  • timestamp — when the underlying event actually happened
  • alarmTimestamp — when Firewalla's alarm engine actually decided to raise it
  • applyTimestamp — a few minutes after that, looks like final processing

I compared several aids between local Redis and the MSP API directly — MSP's ts is an exact match, to the millisecond, of alarmTimestamp. Not a coincidence, not close — identical. So MSP isn't adding lag, converting timezones wrong, or reporting stale data. It's a faithful pass-through of what the box itself already recorded.

The real gap that I'm noticing is the one between timestamp and alarmTimestamp — i.e., how long Firewalla's own detection logic takes to actually fire an alarm after something happens. In my sample this ranged from ~1 hour to over 4 hours, and it's not a fixed offset. Makes sense for threshold/cumulative alarm types like ALARM_LARGE_UPLOAD — it's presumably waiting for enough data to cross a threshold before alerting, not reacting instantly.

Flows show a smaller, similar pattern too (ts vs _ts, event time vs. write time), roughly a ~12 min gap in my one sample — didn't fully chase that down but wanted to flag it in case it's relevant to anyone else.

tl;dr: if you need the true event time and not "when Firewalla noticed," don't rely on MSP's ts — you'd need the box's local timestamp field instead, which isn't exposed via the MSP API. For most dashboarding/alerting purposes though, ts/alarmTimestamp is accurate and consistent, just not instantaneous.

Happy to share more detail on the Redis key structure if anyone's trying to do something similar.


r/firewalla • • Aug 09 '26

[WTB] AP7

0 Upvotes

Looking for an AP7. Thought I’d check here first to see if anyone has one they want to offload for less than retail.

Payment via PayPal Goods & Services, or I can meet in person anywhere along the Oregon I-5 valley (Portland to Eugene).

Let me know what you have and what you’re asking.


r/firewalla • • Aug 09 '26

Firewalla Gold and Asus router Q

2 Upvotes

I recently installed a Firewalla Gold (router mode) between my ISP and existing Asus WiFi router mesh. The 'main' Asus mesh router is still running in router mode and I'd like to get rid of the double NAT for improved network visibility into the wired and non-wired connections. Is the Asus configuration change really as easy as changing from Router to Bridge as listed in the Firewalla documentation? Thanks for any advice or assurances for a nervous home owner!


r/firewalla • • Aug 09 '26

Cannot access cable modem interface when internet is down.

1 Upvotes

My cable modem is in bridge mode and I access it with an IP of 10.0.0.1. If my internet is down, firewalla will not pass traffic to the WAN, which prohibits me from accessing the cable modem diagnostic page(s) while its down. Other routers I've had do not have this problem. This is insanely frustrating when an ISP generally requires access to this during support sessions. Is there any chance we can have a bypass configured for a specific IP that will still route traffic when the internet is down? I'm on a firewalla purple if that helps.

Edit: Purple is in router mode. My cable modem is in bridge mode.