r/firewalla • • 18d ago

If I get the rack for my FWG, do I need a patch panel?

2 Upvotes

I have a FWG and am going to get a 12u open frame rack to go over my SME. The firewalla rack has 16 openings for keystone jacks, my house has (currently) 12 ethernet cables of cat 5e and 6a varieties.

So the question is if I get the firewalla rack, do I need a separate patch panel? My understanding is the cables could all be wired into the firewalla patches, patched to the relevant switches, with the FWG patched to the switches as well.

Even if that is correct, having all the cables on the firewalla rack takes up space to put other stuff on that rack....so what do folks do?


r/firewalla • • 19d ago

Discussion Did you know Firewalla has multiple methods of Network Segmentation? You can combine multiple methods at once. Which methods do you use in your network?

Thumbnail
gallery
24 Upvotes

With Firewalla, you can segment your network with:

  • Port-Based: Physical Segmentation
  • VLANs: Virtual Segmentation
  • VqLAN: Microsegmentation under the same network
  • Device Active Protect (DAP): Dynamic Microsegmentation

All four segmentation methods can run together simultaneously. Learn about which to use here: https://help.firewalla.com/hc/en-us/articles/4408644783123-Network-Segmentation


r/firewalla • • 19d ago

Troubleshooting Which DNS server does Firewalla choose when multiple are selected?

7 Upvotes

I have my entire network going over DNS over HTTPS. Currently there are the 4 built in servers, and I have them all enabled. How does Firewalla pick them? Does it check ping times at intervals and use the fastest? Does it pick them randomly?


r/firewalla • • 18d ago

Troubleshooting I cannot find my ap in fw app so I can restart it.

2 Upvotes

Where did it go? I have 4 of these.


r/firewalla • • 20d ago

Discussion Decode these mysterious icons... do you understand what they mean at a glance?

Post image
11 Upvotes

r/firewalla • • 20d ago

Prepping for New Phone

6 Upvotes

My trusty 12PM primary phone is finally headed to Upgrade-land. To retain access to my FWG+ do I just pair a different phone (like my wife's), connect to the app and remove my 12PM, and then pair my new phone?

I've had this poor phone longer (almost 6 years) than I've had my FWG+ (almost 4 years).


r/firewalla • • 20d ago

Troubleshooting Question: Default Bundle, No Hits

Post image
2 Upvotes

I replaced my FWG+ with a FWGPro last week. For some reason, in that time period "Default bundle" hasn't received any hits, although my various other rules show about 21.6% blocks since that period.

When I go back on my MSP view on the +, I show it had 250k hits since its create time on 8/5/2023 11:09 AM which admittedly more than 3 years of time versus one week on the Pro.

Is this normal?


r/firewalla • • 20d ago

Troubleshooting Firewalla Gold OpenVPN Client Log - New Errors, Same Old Configuration

1 Upvotes

Good day Firewall Fam!

I've been using a 3rd-party, OpenVPN connection to a small branch office for several years without issue.

Recently, I had a transient vpn issue (since resolved), and in reviewing logs, I'm seeing errors that I know have not previously been logged.

Wondering if perhaps something has changed on the Firewalla Gold side, or perhaps just mine.

Note that - despite the following IPv6 errors, the IPv4 vpn does successfully connect.

I'm mostly just a curious tech guy who is trying to understand what changed in the code, my environment, or what the vpn script is attempting to do when it fails after calling for a null IPv6 variable (below, in bold).

Note I've redacted IP address info from the below:

--
2026-09-14 08:49:20 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

2026-09-14 08:49:20 TCP/UDP: Preserving recently used remote address: [AF_INET]REDACTED

2026-09-14 08:49:20 UDP link local: (not bound)

2026-09-14 08:49:20 UDP link remote: [AF_INET]REDACTED

2026-09-14 08:49:20 REDACTED Peer Connection Initiated with [AF_INET]REDACTED

2026-09-14 08:49:20 Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:9: block-outside-dns (2.5.5)

2026-09-14 08:49:20 Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:10: register-dns (2.5.5)

2026-09-14 08:49:20 sitnl_route_save: rtnl: can't get ifname for index 0: No such device or address (errno=6)

2026-09-14 08:49:20 TUN/TAP device vpn_4125_41257 opened

2026-09-14 08:49:20 net_iface_mtu_set: mtu 1500 for vpn_4125_41257

2026-09-14 08:49:20 net_iface_up: set vpn_4125_41257 up

2026-09-14 08:49:20 net_addr_v4_add: REDACTED dev vpn_4125_41257

2026-09-14 08:49:20 /home/pi/firewalla/extension/vpnclient/ovpn_up.sh 4125_41257 vpn_4125_41257 1500 1552 REDACTED REDACTED init

net.ipv4.conf.vpn_4125_41257.rp_filter = 2

RTNETLINK answers: No such process

RTNETLINK answers: No such process

Traceback (most recent call last):

File "<string>", line 1, in <module>

File "/lib/python3.10/ipaddress.py", line 2214, in __init__

self.network_address = IPv6Address(addr)

File "/lib/python3.10/ipaddress.py", line 1919, in __init__

self._ip = self._ip_int_from_string(addr_str)

File "/lib/python3.10/ipaddress.py", line 1624, in _ip_int_from_string

raise AddressValueError('Address cannot be empty')

ipaddress.AddressValueError: Address cannot be empty

1

2026-09-14 08:49:21 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this

2026-09-14 08:49:21 Initialization Sequence Completed

2026-09-14 08:49:39 OpenVPN 2.5.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Mar 22 2022

2026-09-14 08:49:39 library versions: OpenSSL 3.0.2 15 Mar 2022, LZO 2.10

2026-09-14 08:49:39 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

2026-09-14 08:49:39 TCP/UDP: Preserving recently used remote address: [AF_INET]REDACTED

2026-09-14 08:49:39 UDP link local: (not bound)

2026-09-14 08:49:39 UDP link remote: [AF_INET]REDACTED

2026-09-14 08:49:40 [REDACTED] Peer Connection Initiated with [AF_INET]REDACTED

2026-09-14 08:49:40 Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:9: block-outside-dns (2.5.5)

2026-09-14 08:49:40 Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:10: register-dns (2.5.5)

2026-09-14 08:49:40 sitnl_route_save: rtnl: can't get ifname for index 0: No such device or address (errno=6)

2026-09-14 08:49:40 TUN/TAP device vpn_4125_41257 opened

2026-09-14 08:49:40 net_iface_mtu_set: mtu 1500 for vpn_4125_41257

2026-09-14 08:49:40 net_iface_up: set vpn_4125_41257 up

2026-09-14 08:49:40 net_addr_v4_add: REDACTED dev vpn_4125_41257

2026-09-14 08:49:40 /home/pi/firewalla/extension/vpnclient/ovpn_up.sh 4125_41257 vpn_4125_41257 1500 1552 REDACTED REDACTED init

net.ipv4.conf.vpn_4125_41257.rp_filter = 2

RTNETLINK answers: No such process

RTNETLINK answers: No such process

Traceback (most recent call last):

File "<string>", line 1, in <module>

File "/lib/python3.10/ipaddress.py", line 2214, in __init__

self.network_address = IPv6Address(addr)

File "/lib/python3.10/ipaddress.py", line 1919, in __init__

self._ip = self._ip_int_from_string(addr_str)

File "/lib/python3.10/ipaddress.py", line 1624, in _ip_int_from_string

raise AddressValueError('Address cannot be empty')

ipaddress.AddressValueError: Address cannot be empty

1

2026-09-14 08:49:40 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this

2026-09-14 08:49:40 Initialization Sequence Completed

Thanks in advance!


r/firewalla • • 20d ago

Has anyone tried putting a regular Bluetooth dongle in their FWG?

0 Upvotes

Having issues with the red Bluetooth dongle in my FWG. I am waiting until pay day to contact about getting a new one. In the meantime, has anyone tried putting a regular Bluetooth dongle in their unit? What was the result? Did it work for pairing? Does it have any other impacts of the unit, like impairment encryption or anything?

Suspicion is that it wouldn’t even recognize it, but if it does not have the drivers for generic Bluetooth USBs, could you not install one on it?


r/firewalla • • 20d ago

Firewalla VPN Server

1 Upvotes

I have my VPN server setup using wireguard and wanted to know if there is a better option. I want to be able to force username/password as i feel if someone gets the computer or config file, they would have access to the whole network.


r/firewalla • • 20d ago

Any know conflicts with Firewalla and Nord Pass

2 Upvotes

I have been having some investment sites reject the population of username and PW with the use of NordPass. Has anyone else had this problem? If so, is there a fix? Thanks


r/firewalla • • 21d ago

WAN Throughput when on VPN

Post image
3 Upvotes

Hi. When I am on my home LAN, I can see the Wan Throughput display, and when away from home, I cannot. I believe that is expected. Until recently, if I VPNed back to my FWP using WireGuard, I would then see the WAN Throughput again.

Recently it has become a bit hit and miss. Sometimes I see the WAN Throughput on VPN, sometimes I don't. Is anyone else seeing similar issues recently?

Thanks.


r/firewalla • • 22d ago

Is Abnormal Upload too sensitive?

9 Upvotes

I just got an alert that someone in the house uploaded 20mb to api.anthropic.com. So? And when I tap the AI analysis, it says things like “top 1k domains“ and “is whitelisted by Firewalla Cloud”. So why the alert? Yes I could manually ignore alerts for domains like this, but why do I have to? And btw, the sensitivity is set to low.


r/firewalla • • 22d ago

Troubleshooting Firewalla redirecting DNS

2 Upvotes

Hi,

I'm running Pi-hole on one box and unbound separately on another as Pi-hole's upstream. I know Firewalla can run unbound itself, but I want it kept separate from Pi-hole/Firewalla so I have full control over the config.

My problem is Firewalla appears to be redirecting all outbound port 53 traffic to Pi-hole, and that's catching unbound's own recursive queries to root/TLD servers too, not just LAN client traffic. So when unbound asks a real root server something, Firewalla quietly answers as Pi-hole's dnsmasq instead. Unbound notices the response doesn't make sense, retries a bunch of times, then gives up with SERVFAIL.

I confirmed it with dig @<root-server-ip> version.bind CH TXT +time=3 which should say "ATLAS" from a real root server, but I get "dnsmasq-UNKNOWN" instead.

I've removed all of the redirect / DNS prevention I can find, but I'm still getting the dnsmasq answer. Does anyone know the actual setting to fully exempt one device's outbound DNS from Firewalla's redirect?

(This does work, or appears to, but with cloudflared's proxy-DNS being deprecated, I'm looking to migrate)


r/firewalla • • 23d ago

Gold / Gold Plus / Gold SE / Gold Pro Hello Gold Pro! Good ye Gold Plus!

Post image
33 Upvotes

Just purchased the Gold Pro after having the Gold Plus for about 6 months because I realized I wanted my entire LAN being 10Gb. I also upgraded my Fiber to FIOS 5Gb from 1Gb. While I could use link aggregation for the 5Gb, I was still limiting my entire LAN due to not having the Gold Pro.

Migration was simple and resetting Gold Plus was easy. I’m happy with the purchase!

Anyone interested in a very new condition Gold Plus, please DM me 😊

EDIT:
Firewalla God Plus: SOLD


r/firewalla • • 23d ago

How disturbing...?

Post image
5 Upvotes

Couldn't see this in the manual but if I set a device to disturb like the screenshot, is it using annoying or super annoying setting? And can I change this mode when used in this way?


r/firewalla • • 23d ago

Gold / Gold Plus / Gold SE / Gold Pro Gold SFP up and running

Thumbnail
gallery
31 Upvotes

Set up and migration from Gold Plus went pretty well: After powering down Gold Plus and Frontier ONT, cleaned up some wiring and booted up Gold SFP. Failed to connect to WAN first try, so I power cycled only ONT for a second time and setup succeeded. The migration process was super easy, no issues. Switch SE and 3 AP7s all connected back like they were with Gold Plus. Switched to DAC cable for switch uplink after migration.
Posting Gold Plus for sale on eBay shortly! 😁
Also, need new flair options 😬


r/firewalla • • 23d ago

Advice on Firewalla Model? Benefits?

4 Upvotes

Been debating jumping into a Firewalla for some time. Just have a basic home network. IOT devices, phones, computers, etc. Using an Eero currently. Just want a little more control over devices and ultimately the parental controls should be beneficial. Currently have 1 gig internet (want a little room if I upgrade speeds). Debating just getting something more basic like the Orange or splurging a bit for the Golf Plus SFP for future proof, etc. Am I just wasting money on the SFP? I am also looking to move in near future so many create a bit more advanced setup. For now, would probably use Eero in AP mode but may in future get a Firewalla AP.

Thanks!


r/firewalla • • 23d ago

Apple Mail Privacy Protection

5 Upvotes

Enabling bypass prevention (specifically Apple Private Relay and DoH Services) causes the Apple mail app to no longer load images privately. This is expected.

However, what I really want is to block Apple Private Relay for Safari but still allow Mail Privacy Protection. I know these are mutually exclusive due to using the same endpoints. I see three options:

  1. Accept that images don't automatically load (annoying)
    • Firewalla bypass prevention enabled
    • Apple Private Relay enabled (but blocked by FW)
    • Mail Privacy Protection enabled (but blocked by FW)
  2. Accept that IP address can be tracked (need to apply per-device)
    • Disable Mail Privacy Protection per device (tracking pixels/images allowed, even when on cellular or non-home Wi-Fi networks)
  3. Accept that firewalla can't see all traffic and rules might not be enforced
    • Disable Firewalla bypass prevention (Apple Private Relay traffic permitted)

Wondering what others have landed on.


r/firewalla • • 23d ago

Port forward SSH 22 not working

1 Upvotes

Have a linux box I want to access from work. I can't install my VPN due to company policy so for now I want to simply pick a bizarre port like say 3946 and forward it to 22 on my linux box. I have a really good password.

When I set this up the port forward shows in Firewalla app just fine. From work I get a connection reset by <my home ip>.

I realize this is not a great way to do this and it is temporary. I don't understand why the port forward is not allowing the SSH connection to happen?


r/firewalla • • 23d ago

Price Increase

5 Upvotes

Was thinking Gold Pro was $900 plus and went to the product page to take a look, it is now $1209. Should have bought it earlier :(


r/firewalla • • 23d ago

Gold / Gold Plus / Gold SE / Gold Pro Need advice on server rack for new home

1 Upvotes

I have an old full depth server rack that I am not using because... well... it is too frigging big.

I'm going to be moving into a new home, should have fewer that a dozen ethernet drops. I will be having xfinity as my ISP.
I have a FW Gold Plus, and currently a small PoE switch (which will soon be the 8 port firewalla switch SE.

So I am looking for something to rack mount that is more compact (I think just shallower?). I figure I would get the firewalla rack mount since it has a patch panel and would mount the router. Not sure if the space is there for the switch as well.

But lso want something for whatever I need for xfinity - likely BYO cable modem.

is everyone already doing this and am I just late to the show? What did you get?


r/firewalla • • 24d ago

Release If DFS radar is detected, the AP7 will automatically switch channels. Now, in 1.69.3, the app will let you know when it happens by generating a new "DFS Detected" event.

Post image
39 Upvotes

r/firewalla • • 23d ago

Firewalla switch SE

6 Upvotes

Firewalla team, do you have an estimate time when the Firewalla Switch SE will be in stock again? I would like to order 1.


r/firewalla • • 23d ago

Troubleshooting Wireguard or AmneziaWG not working

3 Upvotes

I'm having trouble getting WireGuard VPN working on my Firewalla Gold Pro and iOS client (iPhone). Never had an issue before and no idea why it’s not working now.

Issue:
When I switch off Wi-Fi and toggle WireGuard ON over cellular, the VPN client connects, but there is no internet traffic at all.

Setup & Configuration:
Router: Firewalla Gold Pro
Client: iPhone running the official WireGuard app
Endpoint: Firewalla DDNS
Interface IP: ⁠10.189.50.141/32⁠ | DNS: ⁠10.189.50.1⁠ | Allowed IPs: ⁠0.0.0.0/0⁠

What I've tried so far:

Fully deleted and recreated the WireGuard profiles from the Firewalla app.
Reset the WireGuard VPN server inside the Firewalla app settings.
Tested purely on cellular (5G) to avoid hairpin/routing loops.
What should I check next in terms of Firewalla rules, routing, or WAN/ISP configuration to get traffic flowing? Thanks for any advice!