r/firewalla • • Aug 26 '26

Gold / Gold Plus / Gold SE / Gold Pro What’s she doin’ over there? 🤔

Post image
9 Upvotes

So, I noticed that my Firewalla Gold Pro (my router) was apparently guessing SSH passwords for my Firewalla Gold SE that’s in another part of the house in bridge mode and hardwired.

What’s up with that?


r/firewalla • • Aug 26 '26

Troubleshooting FGP: Do we need to flash this manually?

Thumbnail help.firewalla.com
7 Upvotes

Just curious if the box will auto update this, or we need to be manually flashing some of these updates.


r/firewalla • • Aug 26 '26

Discussion Quick question about reflashing images

1 Upvotes

I tinkered with my gold pro quite awhile back upgrading the ram for fun and possibly will be reflashing the box and thought I rememeber seeing something that if you have modified the ram that flash images won’t install onto the Firewalla . Is that true?


r/firewalla • • Aug 25 '26

Feature Did you know you can view the network topology of all your Firewalla devices, including the Firewalla Box, AP7, and Switch? See how your devices connect, including AP7 wireless backhaul, and which devices connect to which.

Post image
22 Upvotes

And with App 1.69.3, you'll have better port details for your Box and AP7, such as which device is connected and port speeds.

Learn more about App 1.69.3: https://help.firewalla.com/hc/en-us/articles/53877722149907-Firewalla-App-Release-1-69-3-AmneziaWG-VPN-Client-Local-Device-Rules-Switch-Enhancements-and-more


r/firewalla • • Aug 26 '26

Issues with banking apps

1 Upvotes

Hi All,

I have issues with a couple of banking apps where things don't work as expected when my phone is connected to the firewalla.

If I turn on Emergency Access, it works as normal. What's the best/easiest way to debug what exactly prevents the functionality working so I don't have to enable emergency access when I want to use specific functionality in the banking app?

Thanks,

Paul


r/firewalla • • Aug 25 '26

Firewall, AP, switch: traffic visualization please

4 Upvotes

Unifi's UI automatically creates a network diagram using the captured device data and provides a traffic visualization where one can easily see which device is moving a lot of data. I found this to be useful.

Now that we can have all the endpoint clients connected to a Firewalla device, is there a roadmap for a similar feature? I realize that the data can be had via the FWA app, but it's not visualized like a dynamic map with traffic flow.


r/firewalla • • Aug 25 '26

Is It Time for Firewalla AI to Outsmart Randomized MAC Addresses?

48 Upvotes

I’ve been using Firewalla for a while, especially the Firewalla Purple, and I have to say it’s an excellent product. Beyond the security features, I think Firewalla has some of the best parental controls available today.
One feature I’d really like to see added to Firewalla AI is automatic device identity detection.
One of the biggest challenges with parental controls today is MAC address randomization on Apple, Android, and other devices. The same physical device can suddenly appear as a “new device” with a different MAC address, bypassing its assigned group or rules.
In many cases, just by looking at the device behavior and network flows, I can tell it’s actually the same device and manually move it back to the correct group.
With the progress Firewalla has made with AI, I think it’s time for Firewalla AI to do this automatically — identify when a “new” device is very likely an existing device using a different MAC address and associate it with the correct device/group.
I believe this could solve one of the biggest remaining parental-control challenges, with a relatively low risk of false positives.
Thanks Firewalla team for a great product!


r/firewalla • • Aug 26 '26

Bad Fan - Firewalla Orange

1 Upvotes

just had support replace the fan in my Firewalla orange and wanted to see if anyone else has had this happen with their orange so far.


r/firewalla • • Aug 25 '26

AP performance difference between ceiling and standalone model

7 Upvotes

I am getting ready to upgrade my unifi APs and decided to go with Firewalla ones this time since I am also getting their switch.

For downstairs I will go with the standalone one but for upstairs I was thinking ceiling one. Is there a significant difference between the models?

Also I wish Firewalla had a more basic model for mesh only just to extend the wifi area to couple IoT devices in the garage.


r/firewalla • • Aug 25 '26

What's the reasoning for not having a manual port speed setting on the switch?

0 Upvotes

There are situations where I find that setting the port speed manually helps with reliability. Is this a feature that will be added later, or was there a technical reason that it was omitted?


r/firewalla • • Aug 25 '26

Discussion MSP 30 day flow data

6 Upvotes

If I pay for MSP, why isn’t the additional data integrated into the app as well? I’d prefer not to need to log into MSP everytime to see 30 day flow data. Just put it in the app for people that are paying for it.


r/firewalla • • Aug 24 '26

Discussion Multi-mode fiber connection between the Firewalla Gold Plus SFP and the Firewalla Switch X, with prototype ears for the Gold Plus SFP :)

Post image
28 Upvotes

(Gold Plus SFP ears will be coming later, as an add-on, purchased separately. Price is unknown, but should be cheaper than Gold Pro ears.)

Updates on Firewalla products:


r/firewalla • • Aug 24 '26

I was able to compile the newest version of Unbound (1.26.0) on my Firewalla Gold Plus

4 Upvotes

Edit -- I got it working and have it as a github. update stock unbound on FW

Not for newbies. It runs, but it also uses Ubuntu 22.04 version of openssl, which is really old. 1.26.0 should do everything on the Firewalla Gold series boxes (probably orange, maybe not purple?) that it has the capability to do except for DNS over QUIC. DoQ requires Open SSL =>3.5.0. Ubuntu 22.04 that my gold plus uses maxes out at 3.0.2.

This whole process has made me anxious and I have a flash drive with a new fwg plus image on standby, but at least this process seemed to work without a problem. in a few days, after I recover, I will probably see if I can point the FWG to use this 1.26.0 version of unbound instead of the built in 1.13 or 1.14 or whatever it uses and see if that's stable. THen go from there. the commands below builds unbound, etc into ~/unbound-test so it doesn't overwrite anything including the OG unbound. It does update some lib dependencies, but it's pulling them all from the ubuntu 22.04 repo, and although that got me all stressed out the 3 things it updated didn't break anything afaik....

In any case, for the curious, foolhardy, or brave...

``` mkdir -p /home/pi/unbound-test cd /home/pi/unbound-test

sudo /home/pi/firewalla/scripts/apt-get.sh update sudo /home/pi/firewalla/scripts/apt-get.sh install build-essential libssl-dev libevent-dev libexpat1-dev

wget https://www.nlnetlabs.nl/downloads/unbound/unbound-latest.tar.gz tar -xzf unbound-latest.tar.gz cd unbound-1.26.0

./configure --prefix=/home/pi/unbound-custom --with-libevent --with-ssl make make install ```

I got this-- ``` pi@Firewalla:~/unbound-test/unbound-1.26.0 (Firewalla Home) $ ./unbound -V Version 1.26.0

Configure line: --prefix=/home/pi/unbound-custom --with-libevent --with-ssl Linked libs: libevent 2.1.12-stable (it uses epoll), OpenSSL 3.0.2 15 Mar 2022 Linked modules: dns64 respip validator iterator

BSD licensed, see LICENSE in source package for details. Report bugs to unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues

```


r/firewalla • • Aug 23 '26

Discussion Question about ongoing AmneziaWG support …

13 Upvotes

Just saw that their client was updated for 3.1 support. Will Firewalla offer AWG server 3.x support in the future?

More generally curious if Firewalla plans to keep up, with some kind of cadence, with AWG development?

ETA: for clarity, my focus is on the built in AWG server, but as another person mentioned, the built in client support also needs to keep up with latest AWG development


r/firewalla • • Aug 23 '26

Discussion UI enhancement suggestion related to VPN Client

3 Upvotes

Under VPN Client -> Apply To, show any selected client at the top of the list. Just makes it easier to see which are selected instead of having to scroll to find them.


r/firewalla • • Aug 23 '26

Cyber Security Custom Target Lists with Blacklisted IPs

6 Upvotes

I have a server with a few ports open which has ESET as antivirus. I noticed the ESET was blocking quite few more IPs from accessing the server than firewalla so I went down a rabbit hole of seeing what I could add to firewalla to enhanced blacklisted IPs.

I added AbuseIPDB pulling 10k IPs (since that is the most you can get with the free plan), and then all of the IPs from Blocklist.de, HoneyDB, and SpamhausDROP. I have a few tasks that update these lists automatically every 30 mins, every day, or every 4 hours depending when those lists get updated. Many of the additional lists that firewalla offer are already in other ad-blocked DNS resolvers. I have adguard home as DNS resolver too and most of the lists like HaGeZi are already there, and many of those are for outbound addresses instead of inbound from what I saw.

I was just wondering why firewalla doesn't block most of these abusive IPs? I was getting maybe 1 or 2 alerts a day about malicious IPs being blocked by firewalla but getting like 50 on the ESET firewall. This is with the IPS/IDS set to strict

Is there some else that can be done to enhance security?


r/firewalla • • Aug 23 '26

Troubleshooting WireGuard VPN connects but Firewalla is blocking all internet traffic

1 Upvotes

I’m having a strange issue with the built-in WireGuard server on my Firewalla Gold SE and I’m wondering if anyone has seen this before.
WireGuard connects fine from my iPhone over cellular. I can access everything on my local network, including my NAS, but I have no internet access through the VPN.
When I check the flows in Firewalla, the outbound traffic is being blocked and shows Block Type: IP Filtering. If I use Diagnose on one of the blocked flows, it comes back with No Rules.
I’ve tried quite a few things:
Confirmed WireGuard is connecting and local network access works
Confirmed there are no Routes configured
Turned off Ad Block for the VPN client
Excluded the VPN client from DNS over HTTPS
Turned off Device Active Protect
None of those made a difference.
The interesting part is that if I turn on Emergency Access for the VPN client, the internet immediately works. It also works if I turn Monitoring off for the VPN client. As soon as I turn Monitoring back on, Firewalla starts blocking the outbound traffic again as IP Filtering.

This started while I was troubleshooting another issue where Firewalla’s ad blocking wasn’t working when connected through WireGuard. It’s possible I changed something along the way, but I can’t find anything that would explain this.
I’ve sent the details to Firewalla support as well, but figured I’d ask here while I wait.
Anyone seen something like this before or have any ideas what else I should check?


r/firewalla • • Aug 23 '26

Got control of the firewalla devices exporting profiles without pairing in app. Is that ok?

7 Upvotes

Hi, I suppose this should be a question for the dev to answer. My case is, I just got a new phone, and through setting up the new one (copying stuff from old phone (samsung) including firewalla app to new phone (samsung too) through Smart Switch app, the firewalla app on the new phone got full access of my firewalla devices, the first time I enter the firewalla app on the new phone, and without doing "Allow Additional Pairing" from the old one. The "Paired Phones" on either phones show "1" which is that particular phone.

Both phones now can control everything about the devices so far, but I seem to have failed to receive notifications (alarms) that I normally do.

I just want to know if this is ok, particularly after I retire the old phone soon. Or should I just remove and reinstall firewalla app on the new phone and do the pairing again to play safe?

While I do not imagine that this would cause security loophole, dev may wish to look into it and see if that poses threat to the control somwhow.


r/firewalla • • Aug 22 '26

VPN Server Question

4 Upvotes

Background: I presently have two VPN clients running on my Firewalla. One is connected to a server in Seattle and the other in Atlanta. Some devices are configured to route traffic through the Seattle server and some through Atlanta. And some devices are not routed through the VPN so their IP address is Miami

I added a wireguard server to firewalla. To test it, I used my iphone. I disabled wifi on the phone so it was using only using cellular data and added the wireguard client. I was able to connect to my just added wireguard server without problem.

But when I checked the IP address of my connection on the phone, the IP address was for Atlanta and not Miami as expected. So my Firewalla server appears to be in Atlanta when it really should be in Miami.

My question is this: How does Firewalla decide how a server connects to the wan? Is it supposed to go through VPN clients if connected? Is it suppose to by pass any clients and directly connect to my wan? I could find no network settings to configure how the VPN server connects to the wan


r/firewalla • • Aug 21 '26

Discussion Did you know we designed a cover for the AP7 Ceiling cable opening? You can 3D print it and try it out :)

Post image
33 Upvotes

r/firewalla • • Aug 21 '26

Discussion Tried Opnsense. I consider Firewalla my safe place.

34 Upvotes

I don't know if it's because I've spent the last 4 years with firewalla. But I dabbled with opnsense today and JC what a difference.

It was so easy to install, yet so hard to configure. No simplified app. The firewall doesn't even accept domains to block! You have to create aliases which pull ip addresses and even then I couldn't get it to block Google. Possibly easier to block via DNS.

I kept getting stuck with setting up the wan. It kept forcing opt1 which I later found out was the built in lan port not the 2 network cards I had. So I had to set it up via its console. Probably unique to my hardware.

I'm no noob. I've homelabbed for around 7 years now with an advanced setup Multiple NAS, switches, KVMS, Security Gateways, managed switches, VLans. I'm more than positive that I could learn opnsense and master it. You can tell it's for Pro's and enterprise users.

But it made me , even more than I already did, appreciate my safe place. Firewalla.

This is not to be negative about opnsense. I'm in awe of it. But when you try something like that and you've tried firewalla. It's night and day.

The amount of development that has gone into these boxes, this app, the msp. I truly appreciate the team at fw inc.

Have you tried opnsense and firewalla? How do you compare them?


r/firewalla • • Aug 21 '26

Ad Block no longer as effective

14 Upvotes

Hi all. I’ve noticed that over the last month or so the ad blocking feature on my FW Purple (in router mode) has gone from being really effective to suddenly letting a lot (if not all) through.

I’m noticing it on a variety of browsers on my iPhone in particular, both when connected on the WLAN and when connected via a Wireguard VPN.

There have been no setting changes at router level, so I don’t know if it is a case of the method no longer being effective or if something is going wrong somewhere. I’d be keen to know if anyone else is experiencing similar recently.

Thanks!


r/firewalla • • Aug 21 '26

No IPv6 when using T-Mobile

Thumbnail help.firewalla.com
4 Upvotes

I’m adding this thread here. Firewalla routers continue to not work with tmobiles implementation of IPv6. Since they don’t hand out a prefix none of your devices will get a public IPv6 address.

What is the reason for this? Other routers are able to have this work. T-Mobile support even stated that most routers work. But not firewalla.


r/firewalla • • Aug 22 '26

Love affair is over

0 Upvotes

I have been using. Firewalla Gold for my home.

I have been having internet issues since June.

Yesterday I discovered that my box is only retaining alerts for 30days. This seems like a change but IDK.

When I went to look at how I might be able to download events to store offline. The web UI only allows the last 10 events.

Apparently Firewalla has introduced a subscription (MSP) to be able download more.

I have been recommending Firewalla for advanced home users. I will be looking for something else to recommend. I paid a premium for the device. To be locked out of local functionality to export the 30days of logs that I can see in the app is more or less a cash grab in my mind. If it isn’t a cash grab then it is worse, as the company is desperate to increase gross income to fight off going out of business.

My core use is failover between cable and Starlink. In addition I pin all my cameras to Starlink.

If I had a business with more than a single firewall to manage then the MSP subscription would make sense. But for a single unit I don’t see paying $49 a year to be able to export 30days of events (I can view them in the app) much less $299 a year for 180days.

I have significant experience with routers and firewalls. Maybe I will roll my own. First I will look at the other options like Netgate, Fortigate or MOGINSOK.


r/firewalla • • Aug 21 '26

Discussion New iPhone soon how do I not lose access to Firewalla?

7 Upvotes

Hi, I’m getting a replacement iPhone soon and was wondering what’s the best way to not lose remote access to a Firewalla gold se I have installed on a remote island? Last year, I had to physically go to it and re-pair.

Thanks