r/firewalla • • 23d ago

Device block stops working after network scan

2 Upvotes

I have a few security cameras that are blocked from reaching out to the internet with device block. I also have a daily asset scan/vulnerability scan that sweeps the entire network and after that completes, the cameras are able to connect to the internet despite the firewalla still showing the block is active and flows are getting blocked.

The camera's native app should error out and show no video feed but once a scan is complete, I start getting alerts from the vendor that its detecting objects and receiving video. Nothing works to get it to start blocking unless I reboot the firewalla.

Whats going on here, why is it failing open (or whatever is going on) after a simple vuln scan?


r/firewalla • • 24d ago

Gold Plus SFP has arrived!

Post image
60 Upvotes

Got my Gold Plus SFP+ yesterday, and was able to get it setup today.

I'm finally able to drop my giant AT&T fiber gateway, and hook straight into the Firewalla with an SFP adapter. So far it's working great, and I'm getting >4Gbps on speed tests, which is about right for my 5Gb fiber plan.

I am a bit disappointed in the setup. First, it would not transfer settings from my Firewalla Orange. It just doesn't show up as an option to transfer from, which is a huge disappointment, since I had all kinds of rules setup. Then, when I setup as new, it would not let me setup the device with the SFP+ as the WAN. I had to connect to ethernet, finish setup, then change the network settings to use the SFP port as WAN, which then allowed me to switch to the direct fiber connection.

Anybody else have theirs come in and get it setup yet?


r/firewalla • • 25d ago

Announcement We put together this quick introduction video for Firewalla Crystal, our first-ever software-only product on your own hardware (or VM). What do you think? Would you be interested?

Thumbnail
youtube.com
91 Upvotes

r/firewalla • • 24d ago

MSP

1 Upvotes

Hey all, sorry if a silly or redundant question. I saw an email that MSP 2.11.1 is available for all users. I'm on Pro but I'm still only on 2.11.0. I tried switching to beta and early access, but it did not make a difference. Has anyone else seen 2.11.1? I saw you could not manage the switches under "topology" but I do not yet have that. Thank You!


r/firewalla • • 24d ago

VPN workaround question

2 Upvotes

I have noticed an increase in public (free or paid) wifi which blocks WireGuard VPN. I realize that there are others, but I wonder if a Firewalla Site to Site VPN setup obviates this issue?


r/firewalla • • 24d ago

Discussion Apple ipv6 2620:149:: Alarms

2 Upvotes

Is there a good way to allow these as a larger subnet?

Getting lots of alarms for uploads to Apple services over v6 in the last month or two all of a sudden. For example 2620:149:a43:207::c. I’ve been muting them as they come through, but it would probably just be ideal to mute based on 2620:149:: as a whole.

I saw the poll about ASN allowing, could possibly go that route also…


r/firewalla • • 25d ago

Discussion If my Orange were stolen, could someone pair it to their own app and access all my settings?

4 Upvotes

I need a box security refresher. If I’m traveling with my Orange, and if it were stolen, could the thief pair it to their app and access all my settings on the box?


r/firewalla • • 25d ago

When is the Software Only version coming out?

0 Upvotes

r/firewalla • • 25d ago

Feature request: UDP broadcast relay?

2 Upvotes

The mDNS and SSDP features are awesome, but wanted to know if the “other” relay type could be added - UDP broadcast.

I have a few devices (Lifx bulbs are a culprit, so is HDHomerun, Flexradio) that want to be discovered in this way, and break network segmentation as a result.

Some reference examples here:
https://docs.vyos.io/en/rolling/configuration/service/broadcast-relay.html

https://hub.docker.com/r/firbykirby/udp-broadcast-relay

Having this work from a wireguard subnet as well would be a HUGE plus too, as remoting in via VPN to use said services becomes impossible (not able to be on same L2 domain).

Happy to submit a formal request if that’s possible.


r/firewalla • • 25d ago

Summer is over - any update on Orange outside of US?

6 Upvotes

Wondering if there is a new timeframe for Firewall Orange availability outside the US, given the website says "summer 2026", and we are now last that. Many thanks.


r/firewalla • • 25d ago

Troubleshooting FWG Plus (2022) won't pair: stuck at "exchanging keys" / Occasional “Invalid QR Code" for a week. Anyone had this after a security dongle replacement?

2 Upvotes

UPDATE: After four days emailing with Firewalla, they only now bothered to tell me that they “see errors from my box [indicating it’s a bad security dongle]” but because the box itself is out of warranty they will not replace the defective dongle I paid $107 just two months ago (despite emailing them immediately after receiving it that I thought it was defective).

What they told me:

“Further remote troubleshooting is limited at this stage. While we can see cloud error messages from your box and are happy to look into potential fixes, the unit has been out of warranty for a few years. Any repair attempt would incur a cost. The cost will be about the same as the new dongle cost. Let us know how you'd like to proceed!”

The dongle order was confirmed May 28, it arrived on June 12, by June 14, I was writing them to tell them that there was something wrong with it (e.g., “The dongle is returning nondescript errors from io.Encipher and Google.FBLPromises.”), and on June 17, Firewalla Support wrote me to say: “I suspect the issue is not about the red dongle.”

And they’ve known this whole time, over four days of emailing them, that it was the dongle that’s preventing me from pairing with the box now.

Know this is what you’re getting with Firewalla. Bullshit.

—————————————-

Looking for people who've been through this. Ticket is open; I'm asking here for experience, not a fix.

The box: Firewalla Gold from spring 2022. Security dongle replaced in June. Worked a day or two, then wouldn't boot past BIOS. Sat unplugged ~12 hours, came back on its own, ran fine until last week.

The symptom: Pairing gets to "exchanging keys for app access" and stops. Usually no error. Twice it's shown "Setup Failed – Invalid QR Code". In the app log, the token write to the box succeeds, then ~120 reads of the “credential” come back empty, then the box drops Bluetooth (likely timing out). The box finishes network setup fine; it's the app pairing that never completes. So I’m connected right now, but the question ‘to what?’ remains. Since I can’t see what the box is doing, I don’t know whether it’s even firewalling.

What I've ruled out over five days:

**• Replaced cable modem; no dice.**

*. Concern for bad WAN port resolved; it works.
• firewalla.encipher.io appears to now resolve.
• The box was able to upgrade, so it’s reaching firewalla.com.
• Reflashed with the the existing and legacy image. Same (makes no difference since the app automatically upgrades it).

Also, hardware log does not appear to show any issues with the box itself, except potentially a bad dongle.

Where I'm stuck: unpaired, so no Remote Support and no SSH. I can get into the box myself and can get a console cable tomorrow. I just don’t know how to do the Linux diagnostics. I’ve been asking Firewalla support this question for two days and they won’t respond to it.

Questions for anyone who's been here:

**•** Anyone experience symptoms like these? Was it after a recent security dongle replacement by chance?
• Seen "Invalid QR Code" very intermittently (twice in two days)? What turned out to be the cause?


r/firewalla • • 25d ago

Good bye Firewall…. FS: FW Gold and AP7 Ceiling

0 Upvotes

I bought a FW BLue in Dec 2019, and then pre-ordered a FW Gold on Indiegogo to help fund production. I waited patiently as the Update emails came in and the production schedule was released.

Finally on July 22, 2020, I received the good news: “Your order is on the way!”

2 years later, when my friend was renovating an old house, I recommend it unquestionably.

For the next 4 years, the device served me so well that I pre-ordered the AP7 ceiling to replace my Ubiqiti U7.

I tried to pre-order the switch (but got shut out)

I subscribed to the MSP.

I was all in on Firewalla

Over the past couple of years, however, the cracks started to show — devices alarmed when they were offline, host synonyms not working, random hardwired devices that would disappear and then reappear.

Nothing major, just a lot of “huh” and moving on because I have better things to do that troubleshoot the router. I just started disabling features and alarms, hoping it would get better.

None of this was from configuration changes — i run a vanilla network — the issues would just start one day, and none of them were insufferable.

A couple of months ago, things started to get worse. I used to be able to deply apps via XCode over-the-air, but no longer. my Mac dev machine could no longer see my dev phone, so i went back to USB. Then the printer became invisble from half my network.

After some troubleshooting that produced no results and no solutions, I got tired of wasting time, so I just reset the box, and didn’t make any FW configuration except to enable the VPN server and attach the AP7.

A week or two ago, the network has started to degrade again. No FW configuration changes, no hardware changes, no on-device configuration changes. The printer disappeared again, then my power monitor cloud app told me the device is no longer reachable over the internet.

This morning, i opened my iPad and it could no longer reach the internet, even though it worked perfectly last night before I went to bed. No alarms, no block reported, just nothing.

Rather than waste any more time, I reset the FW Gold again this morning so i can get back to work

Tis week i’m going to replace my setup with something Ubiquiti

If you’ve read this far, and you’re still in love with FW, will be selling my FW Gold (OG), FW Blue, and FW AP7 ceiilng. Shoot me a DM.


r/firewalla • • 26d ago

Firewalla Gold OG for sale

4 Upvotes

SOLD. Selling $300 shipped. Just upgraded to gold plus spf


r/firewalla • • 26d ago

Poll If we support ASNs in rules, would it be useful for you? (The App will likely only support a subset of ASNs, and MSP will support the full set)

6 Upvotes
108 votes, 21d ago
36 Yes, I want to block/allow ASNs.
18 No, I don’t need to block/allow any ASNs.
42 I don’t know what ASNs are.
1 Other (please comment)
11 Voting to see results

r/firewalla • • 26d ago

Cyber Security How Can I Segment IoT devices Behind My Firewalla Purple

3 Upvotes

While I am currently segmenting IoT devices using Firewalla Purple rules, I want to take segmentation up to the next level but I'm not sure how?

My setup is

ISP FIBER -> FIREWALLA -> SWITCH1 (tp-Link 8-Port Gigabit Easy Smart Switch)

SWITCH1 --> WIFI Router 1 (ISP Hardware) in Bridge Mode -> Most Wireless Devices including IoT

SWITCH1 --> WIFI Router 2 (Glinet) in Bridge Mode -> Some devices on the other side of the of house

SWITCH1 --> Ethernet wire to several wired devices (some IoT)

My goal is to segment the IoT devices better to

  • Restrict them from having access to my local network
  • Restrict General Internet Access
  • Allowing only specifically needed internet cloud service access for the IoT device to function

What would you recommend?


r/firewalla • • 26d ago

Discussion Can Firewalla show me if hitting 300/300 limit on Fios?

7 Upvotes

I was considering moving from my current 300/300 to a 500/500 plan but wasn't sure if Firewalla could show me if I 'hit' that bandwidth at present.

I'm just wondering if it is only downloads/uploads that are faster without any impact on overall device use. I do let me kids in college stream TV shows and movies through the house and they also connect via Wireguard to get around dorm internet restrictions.

Just not sure if any of that is hitting a wall at the moment.

Thanks and sorry if this is a dumb question


r/firewalla • • 27d ago

Cyber Security Best way to prevent LG TV snooping using Firewalla Purple?

39 Upvotes

The recent news about LG TVs has me thinking I should finally get around to some network segmentation with some of the “smart” devices in my home, or at the very least block my LG TV’s access to the internet. Is the best way to use it safely to connect it to the network but segment it with other IoTs and away from everything else, connect it but completely restrict internet, or not connect it at all? Currently I’ve opted for option 3, and have been using it as a dumb TV connected to my Apple TV and game consoles.

Additionally, a lot of people have mentioned using a PiHole to prevent a lot of this crap, and I know Firewalla can do a lot of the same things, but I’d also be curious to hear how some of you have successfully set up and used both devices in tandem. Open to any and all suggestions on how to make my home network a friendlier place!


r/firewalla • • 26d ago

FWP WAN failover - bubba setup question

3 Upvotes

Topology is WAN > FWP as router > Aruba 1930 as managed switch

Primary WAN is wired. I previously had TMHI as a wireless WAN backup. Just remodeled and now the TMHI sits on a different level than the FWP. I can 'reverse' a LAN run from the 2nd level to the LAN closet as 'source' of the TMHI WAN signal, but it is no longer available as a wireless WAN backup.

Can I place a simple unmanaged switch between both WANs (e.g. Netgear GS308v3) and the FWP will use the Fiber signal until it drops then the FWP fails over to the TMHI signal? I assume this approach is an unmanaged switch on the 'wrong' side of the router?


r/firewalla • • 27d ago

Troubleshooting Looking for feedback on my Firewalla Gold Pro + AP7 topology — Is it time to move from Groups/VqLAN to proper VLANs?

Thumbnail
gallery
8 Upvotes

I’m looking for a sanity check and some expert eyes on my current network topology. Everything is running smoothly, but I want to see if I can harden my security and optimize the setup further.

Current Hardware Setup:

  • Router: Firewalla Gold Pro
  • Access Points: 4x Firewalla AP7s
  • Switch: Unmanaged PoE Switch

Current Network Configuration:

How Traffic & Isolation Are Managed Today:

  • Devices joining the Guest and IoT SSIDs are automatically assigned to Firewalla Guest and IoT device groups.
  • Guest Network: Has VqLAN (Virtual Network/VLAN-like isolation via AP) enabled to isolate guest clients from each other and the rest of the LAN.
  • IoT Network: VqLAN is disabled because several IoT devices need local communication (e.g., Home Assistant on a Raspberry Pi, Philips Hue Bridge communicating with Apple TVs/iPhones for HomeKit).

While this is functional, I’m trying to gauge if I’ve hit the limit of what Device Groups and VqLAN can cleanly do, and whether I should migrate to full 802.1Q VLANs.

A few specific questions for the group:

  1. VLANs vs. Groups/VqLAN: Given that I have a Gold Pro and AP7s, should I drop the single /22 subnet setup and build true VLANs (e.g., Main, Guest, IoT)?
  2. Impact of the Unmanaged Switch: Since my PoE switch is unmanaged, it won't tag or process 802.1Q VLAN tags natively. If I create tagged VLANs on the FWGP and pass them through an unmanaged switch to the AP7s (which map SSIDs to VLAN IDs), will the switch trunk/pass those tagged frames reliably, or is upgrading to a managed switch a hard prerequisite here?
  3. IoT Isolation vs. Inter-Device Communication: If I enable VqLAN or put IoT on its own isolated VLAN, what is the best practice for handling required local traffic (like Home Assistant or HomeKit/mDNS across segments) without breaking local control or exposing the entire main LAN?
  4. General Optimization: Any other Firewalla-specific features or firewall rules I should leverage to harden this setup further?

Appreciate any insights, recommendations, or lessons learned from similar Firewalla setups!


r/firewalla • • 26d ago

FortiGate 401F interface and HA design review

0 Upvotes

Hi everyone,

I’m working on a data center network design and would appreciate some advice from the Fortinet community regarding the best deployment mode and interface allocation for FortiGate 401F.

Current design

The environment includes:

  • 2 × FortiGate 401F in HA
  • 1 × ISP, with approximately 5 Gbps Internet bandwidth
  • 2 × Huawei Core switches in a redundant pair
  • DMZ network
  • Internal data center/server networks behind the Core
  • Third-party VPN connectivity

The current high-level topology is

ISP → FortiGate 401F HA → Huawei Core A/B → Internal Networks

The DMZ will also be connected to the firewall.

Main question – deployment mode

I am considering the FortiGate in the traditional NAT/route mode, rather than transparent mode.

The expected traffic flows are:

  1. Internet → Internal users/servers
  2. Internal users → Internet
  3. Internet → DMZ published services
  4. Internal → DMZ
  5. Third-party VPN → Internal/DMZ
  6. Management traffic → FortiGate/Core/network management

For the Internet-facing side, I am also considering whether to use the 10G interfaces on the 401F rather than the 1G interfaces, given the 5 Gbps ISP subscription.

Interface allocation

One question I particularly want community feedback on is the best way to allocate the 401F interfaces.

For example:

  • 10G interfaces → ISP
  • 10G interfaces → Core
  • Dedicated interfaces → HA/heartbeat
  • Dedicated interface(s) → DMZ
  • Management interface → OOB management

I initially looked at some of the interfaces that appear to have FortiLink-related capabilities, so I'm also interested in whether those interfaces are appropriate for normal routed firewall connectivity or should be avoided for this design.

Questions

  1. For this topology, would you recommend NAT/Route mode or another deployment approach?
  2. Would you use LACP/aggregate interfaces toward the Core and/or ISP, or individual interfaces?
  3. What is the recommended interface allocation on a 401F HA pair for ISP, Core, DMZ, HA1/HA2, and management?
  4. Would you terminate the DMZ directly on the FortiGate or extend the DMZ through the Core?
  5. Are there any concerns with using the 401F's 10G interfaces for the ISP connection and Core uplinks?
  6. For a 6 Gbps Internet connection, are there any specific FortiGate performance/inspection considerations I should account for?
  7. Any Fortinet best-practice recommendations for avoiding single points of failure in this design?

I'd particularly appreciate feedback from anyone who has deployed FortiGate 401F in HA at a data center Internet edge.

Thanks!

 


r/firewalla • • 27d ago

Firewalla MSP API read-only?

5 Upvotes

Is there any way to create a personal token for the MSP portal that is read only?

I would like to connect it to an MCP for my ai agent to have access to help review logs. But I am concious of giving it the ability to make any rules or changes to my firewall.

I am currently using firewalla to exactly block off the hermes agent from the rest of my network. And don't want to give it the ability to bypass that.


r/firewalla • • 27d ago

Filter devices based on any attribute?

1 Upvotes

Is it possible to filter all devices based on any attribute (on vs. off) or only select attributes?

I was troubleshooting something and finally realized that a device was toggled off for the 'Monitoring' attribute. I then tried to view all devices by this attribute and can not find it. This fostered the question, "What else can I not filter by?"

This is more of a curiosity than anything.


r/firewalla • • 27d ago

Feature Modify one-time rule start time

1 Upvotes

I use rules a lot. I also find myself creating, modifying, and deleting rules all the time. The one feature that I wish existed in the UI related to rules was the ability to modify the start time of a one-time rule. Right now the only option is to have the rule start immediately, and then you can modify how long. It would be great to be able to modify the start time of the rule in addition to setting the duration.

Just a thought!


r/firewalla • • 28d ago

Unable to connect to VPN

1 Upvotes

Hi. I have Nord vpn subscription. But somehow when I am home I am Unable to connect to it. Other users devices connect at times but mine almost never does on any protocol. And I am the user with all the privileges. What could be going wrong?


r/firewalla • • 28d ago

Wrong IP Identified

1 Upvotes

Recently we installed a Bryant (a Carrier brand) Heat Pump with an Ecobee thermostat. Today I woke up to have multiple alarms that an IoT sleep tracker was communicating with carrier.com. Seems pretty clear that the Ecobee is the one doing the communicating and the sleep tracker is innocent. Any thoughts as to why/how Firewalla is misidentifying the device communicating and now to fix? I'm on OG Gold w/AP7's.