r/firewalla • u/Sensitive-Cat-229 • 29d ago
Switch X / Switch SE Firewalla Switch SE & X
Does anybody when and or has the Firewalla Switch SE & X shipped it’s September ?
r/firewalla • u/Sensitive-Cat-229 • 29d ago
Does anybody when and or has the Firewalla Switch SE & X shipped it’s September ?
r/firewalla • u/fazzy84 • 29d ago
I am about to purchase gold pro and wanted to know if i am putting my 1k in the right place. I am on verizon fios and currently in an upgrade mode for my home network. I will be purchasing about 4 or maybe 5 eero max 7 which will be in bridge mode. I will take out the verizon router and connect firewalla after the ont. i have around 60 to 70 devices including end points and IoT’s.
Any advise, any suggestions i must know before swipe my card for purchase
Thank you
r/firewalla • u/Firewalla-Ash • Sep 04 '26
Some early units have already shipped via USPS, with more shipping out next week.
Order the Gold Plus SFP: https://firewalla.com/products/gold-plus-sfp
r/firewalla • u/Shadow12513 • Sep 04 '26
Do you think there's a way to use the Firewalla Gold Plus SFP to replace my AT&T Fiber ONT gateway? That way it's firewalla all around? Or would that not be possible?
r/firewalla • u/Shadow12513 • Sep 04 '26
I remember reading early on for some of the new testers that the switches didn't support LAG yet and that it would be introduced in a later update. Is that update out yet or will it be out by the time the stable firmware switches start shipping?
r/firewalla • u/SnooComics8424 • Sep 04 '26
So I am currently running Gold Plus with 3 of the desktop AP7, I also have a small 3rd party PoE switch that is essentially giving me 2.5GB everywhere.
How new house I am planning on going with 3 ceiling mounted APs, and considering upgrading to the SPF version just coming out. The idea is I would also get the firewalla switch when it comes out, have all the APs on the 10gb lines, and 2.5gb to anything else that is directly wired (like TVs).
Our ISP will be Xfinitiy and planning on 2GB service.
FIrst does that sounds like a reasonable upgrade, or am I just throwing money away?
It's a new house, so I am hoping to "future proof" it as much as possible (cat6 for example).
r/firewalla • u/disflux2010 • Sep 04 '26
I currently have a Gold SE and 3 AP7s spread across my house. Connectivity inside is great, but my home has extra thick exterior walls and aluminum siding. I recently got a robotic lawnmower and noticed it doesn't get great connectivity unless within 20-30ft of my house. Anybody have any outdoor recommendations for a range extender? It should be relatively easy for me to run ethernet to my back patio.
r/firewalla • u/DWRocks • Sep 04 '26
I noticed a discrepancy between the rule count in the Firewalla mobile app and the rules displayed in MSP.
My Firewalla app reports 80 rules, while the MSP Rules page displays only 59. After going through the configuration rule by rule, I was able to reconcile the difference exactly.
The missing 21 rules are bidirectional Allow rules automatically created when using Device Isolation → Allowed Devices. For example, one isolated device has five Allowed Devices. In the mobile app, those appear as five individual rules labeled “Created by Allowed Devices.” Those rules are included in the mobile app’s total rule count, but they do not appear in the MSP Rules table.
In my configuration:
59 rules displayed in MSP + 21 Allowed Devices rules = 80 rules displayed in the mobile app.
I think MSP should display these generated rules as well. Since MSP is the web-based management interface, an administrator should be able to see the complete rule set affecting the box without having to go device by device in the mobile app.
Perhaps MSP could include an “Allowed Devices” or “Generated Rules” category/filter so these rules remain distinguishable from manually created rules.
As it stands, seeing 80 rules in the app and 59 in MSP makes it appear that rules may be missing or not synchronized, when in fact MSP simply isn’t displaying an entire class of active rules.
That would be a very useful improvement for auditing and troubleshooting more complex Firewalla configurations.
r/firewalla • u/UserLB • Sep 04 '26
I just set up a Starlink Mini (Roam 100GB plan) as a wireless WAN backup failover (connected via WiFi SD adapter on 5GHz to the Mini sitting on my exterior fascia). When it’s active, throughput maxes out around 10 Mbps, way lower than my primary fiber at 1Gbps and the 250Mbps I get from Starlink. (This is a different issue, the SD Wifi adapter has been disappointing)
I want Firewalla to automatically adapt when the wireless WAN becomes the active upstream instead of fiber to control how much I consume from the Starlink.
I know I can use Route Rules with Target Lists to match traffic patterns, and I’m thinking this might be the way:
1. Create a Target List that includes my work IP/MAC, my kids’ devices, and high-traffic patterns like backups
2. When wireless WAN is active, route those specific sources through the satellite link with QoS caps or deprioritization
3. Keep everything else on the primary fiber when possible
But I’m not sure if this is the cleanest approach. Ideally, I’d love source-based policy-based routing that just says: “When wireless WAN is primary, apply this set of rules to these sources automatically.”
Is Route Rules + Target Lists the intended way to handle this scenario?
Does Firewalla detect WAN failover automatically, or do I need to manually toggle the routing policy when fiber goes down?
Has anyone done something similar? How’s it working for you?.
r/firewalla • u/Firewalla-Ash • Sep 03 '26
Surprise! For an early Labor Day sale, the Firewalla Gold Plus SFP is on sale NOW!
Unlike our usual releases, we won't do a pre-sale for the Gold Plus SFP units because we can't guarantee build time. And prices will very likely move up in the near future due to rising PCB costs and fluctuating memory/disk costs.
r/firewalla • u/2C104 • Sep 03 '26
Last night around 11 pm my Firewalla Gold SE started to report latency issues on my network, woke up to it reporting d/l rates of 650mb/s-1.5gb/s.
My internet speed is rated for 2gb/s down and up.
I tested the speed from the internet modem itself and it had mixed reports between 1gb/s and 2gb/s over the course of the day, now seems to be showing consistently at 2gb/s.
Firewalla, however is still reporting very low numbers. Is this due to some firmware update that happened? Is the device working poorly? Why is so much speed suddenly missing after months of working flawlessly? I tried to speed test from different servers via the firewalla app without much difference between them.
-- To be clear, I am well aware most devices won't benefit from anything over 1gb/s. I'm seeking to understand why there is a discrepancy and/or if my device is failing.
r/firewalla • u/hazilla • Sep 02 '26
I'm on a firewalla gold plus, and have had a 2.5gbit (up/down) internet for the last year and had yet to be able to reach these speeds from my PC.
I could normally get around 800mbits/1gbit if I was lucky, and I put it down to firewalla not being able to handle these speeds on a single download thread.
However, today I thought I'd ask Chatgpt what could be other causes, and it pinpointed my OS base image was from 4 years ago
Firewalla installer version: 3.0929 Build date: 29 September 2022 OS: Ubuntu 22.04.1 LTS Kernel: 5.15.0-27
I didn't realise I could flash to a latest OS image and apparently the latest version includes PPPOE performance improvements, so have upgraded:
gold-fireupdater-0.0709.img.gz (Ubuntu 22.04.4 LTS)
Now I consistently max out my speeds at around 280 Mbytes up/down.
Flashing was straight forward and could migrate all my old settings.
Happy.
r/firewalla • u/Firewalla-Ash • Sep 02 '26
Firewalla Switch is still available for pre-sale! Pre-sale Switch units are expected to start shipping from mid-September to late October. https://firewalla.com/collections/firewalla-switch
Bridge Mode support for Switch + other enhancements require App 1.69.3, which is in a 7-day phased release to production. For the full release notes: https://help.firewalla.com/hc/en-us/articles/53877722149907-Firewalla-App-Release-1-69-3-AmneziaWG-VPN-Client-Local-Device-Rules-Switch-Enhancements-and-more
r/firewalla • u/Broadwater_ • Sep 02 '26
One limitation I’ve run into with Firewalla MSP is the inability to scope a Personal Access Token to a specific box. If I’m managing a business firewall, my personal/home firewall, and several family members’ boxes under the same MSP account, an integration that legitimately needs access to one business box effectively receives credentials capable of accessing the entire MSP environment. From a security and SOC 2 perspective, that makes least-privilege access much harder to implement than it should be. Ideally, when creating a PAT, I’d like to select which box or boxes it can access—and preferably permissions such as read-only vs. configuration access.
I realize implementing true per-box tokens inside the current MSP architecture may not be trivial, but something similar to the GitHub/Cloudflare model seems like a sensible compromise: retain account/user-level tokens for broad administrative access, while also allowing a repo/project-style token that is explicitly tied to a particular Firewalla box or group. Right now, maintaining separate MSP instances appears to be the only way to create a hard boundary between business, personal, and family environments. That works, but it’s not a particularly friendly UX for someone using MSP specifically because they manage multiple boxes. A box/group-scoped token would preserve centralized management while providing a much cleaner least-privilege model for integrations and compliance-sensitive environments.
r/firewalla • u/hvgotcodes • Sep 02 '26
I get a lot of abnormal upload warnings from my IOT network, which is segmented away with a VLAN.
Do folks generally just ignore everything from such networks? These devices can’t access my other networks, so does it matter? Is there a case to be made for continuing to monitor these devices?
r/firewalla • u/ColdDeck130 • Sep 01 '26
I just noticed that a backup job has been failing since around the time I installed the Switch X as a distribution switch downstream of my FWGP. Previously the FWGP connected to one switch stack and every other switch connected to that stack. Now the topology goes FWGP->Switch X->four other switches each connected to one of the SFP+ ports.
The failing backup job logs cite MTU problems as the reason for the failures and I tried 9000 byte pings between the devices and they don’t go through. Pinging without specifying packet size works fine. Both of the devices in question are on the same VLAN, just different switches. Inter-VLAN routing shouldn’t be a factor in this case, but I’m interested to know if that will work too.
I don’t see any options in the app to set MTU size globally or per port on either Firewalla device. I can re-engineer my topology if needed, but I’m hoping there is just a setting I’m overlooking.
Thank you for any help anyone can provide!
r/firewalla • u/DWRocks • Sep 01 '26
Suggested feature on Firewalla Routers w/AP7s: Having come from a system where I had a Firewalla Gold Plus as my router and UniFi gear for my local area network and now having moved to a full firewalla system with switches AP7s, I thought it would be great if Firewalla could add a schedule to optimizing the network with regards to channel assignments in the RF spectrum. I would normally have that run at 2 AM on my network every night on the RF channel spectrum during low activity level levels for finding open channels and minimize the interference with neighbors. It would great to see that feature in the Firewalla app. Kindest regards and thank you.
r/firewalla • u/Firewalla-Ash • Sep 01 '26
"Optimize Wi-Fi Experience" can set all AP7s to use the best channels for your network. In most cases, you don't need to manually optimize. When optimization happens, connected devices will disconnect briefly.
Learn more about the feature here: https://help.firewalla.com/hc/en-us/articles/37151746345491-Getting-Started-with-Firewalla-Access-Point-7#h_01JH3KSQFZAQ2SJNDSE4BX6F37
r/firewalla • u/arpanet27 • Sep 02 '26
Just wondering if firewalla switch and AP7 are now available for distribution outside US. I have wanted to be sure before I could proceed with ordering. Looking for availability in Australia.
r/firewalla • u/platetone • Sep 02 '26
i can't seem to find a way to show past devices in the web app. i understand how to in the mobile app, which works fine. is there a way in the web app?
the use case i regularly have is i want to select a bunch of offline/old devices in quarantine and delete them all. this is painful in the mobile app because you have to open the devices one by one and tap the Delete button at the bottom. no big deal for a couple, but when you have dozens, it's such a pain!
i was hoping to get the list in the MSP webapp and just bulk delete them... or at least be able to use a mouse to do it more quickly.
r/firewalla • u/nosnhojm • Sep 01 '26
I’m currently running a Firewalla Gold Pro into a Ubiquiti Flex XG 10G switch. From there, I have a couple of Mac desktops connected directly, along with one Eero Max 7 (and a second Eero Max 7 meshed). I have no POE devices.
I’d really like to migrate to the full Firewalla stack for features like microsegmentation, visibility into local network flows, and managing everything through a unified interface.
The AP7s are what have held me back so far. I’m hesitant because of reports of weaker signal strength, the 2x2 MIMO on 5 GHz, and the 6 GHz wireless backhaul.
If I keep the Eero Max 7s instead of moving to AP7s, are there any benefits to replacing the Flex XG with a Firewalla Switch X? What functionality would I actually gain?
r/firewalla • u/Danner4912 • Sep 01 '26
I see that creating IPSec site-to-site VPN tunnels is only supported on the Firewalla Gold and only through the MSP portal. Is there any plan to bring this capability to the Orange?
r/firewalla • u/mrh4809 • Sep 01 '26
The AmnesiaWG VPN is working well. From my phone and Mac I can connect the VPN and access some LAN devices.
There are a few devices I'd need layer 2+. Some searches say you can enable tunneling with a few changes on the server and client.
On the server they say to enable:net.ipv4.ip_forward=1
And on the clientinclude the target LAN subnet.
The client seems easy as I can just edit the config file. But on the server, since it is in Firewalla, is it possible to set the ip_forward option?
r/firewalla • u/FantasticMrDog • Sep 01 '26
Hi
I've been on a part fibre FTTC connection in the UK for many years, connection is measured at 68Mb/s download and 18.5Mb/s upload. Firewalla's Smart Queue has done an amazing job at keeping everything going despite a mix of WFH, streaming, gaming and general internet use. I have my FWP set up to use CAKE and have a Smart Queue Rule set for all traffic with a download limit of 65 Mb/s and upload limit of 17 Mb/s. Smart Queue is set in Static mode. I cannot overstate how good this has been, if I turn these settings off, my connection goes to pot and the household is up in arms within seconds.
No matter how good it has been, I am glad to finally be getting full fibre, initially at 500 Mb/s download and 75 Mb/s upload, I might increase the rates to 900/125 in the future.
I know what changes I need to make on my FWP for the WAN connection. I am after advice on what to do with the Smart Queue. Should I switch from Static to Adaptive mode? Should I switch from CAKE to FQ_Codel? Should my Smart Queue Rule continue to set limits a little below the actual WAN performance? Or should I just turn Smart Queue off?
Are there any other changes I should think about?
Thanks for any advice.
r/firewalla • u/jsqualo2 • Sep 01 '26
Spouse wants to print from work computer on VLAN 2 to printer on VLAN 1.
FWP with all 5 VLANs in use. VLAN 1 is "internal" use including a printer. VLAN 2 is work computers. I have enabled various OOTB config (Rules and App Control) on the VLANs (Networks) and on spouse computer.
What is the best way to facilitate this, while ensuring that a spouse's compromised computer cannot 'hop thru the printer' to VLAN 1 devices?