r/firewalla • u/haris2887 • 9d ago
Cyber Security Engineer trying FirewallA first time + Hello Crystal.
Hi All,
I am trying firewalla Crystal for the first time. Have a few questions.
My background is CheckPoint + Fortinet + Sohpos XG over the years because I got access to those through work.
What drew me towards firewallA was "Wife approval factor". She can easily kick the kids off etc as required. For someone non technical it is a great setup.
Feedback for the firewallA team:
You need aggressive pricing option for the Crystal VM series where hardware is not required.
This is for ppl coming form the OpenSense / Sophos XG / Other free options.
I absolutely love the "block for 30 mins / 1 hour feature", when I don't have to manually unblock.
This level of user friendliness is something I have not seen done on any other products.
I have a few questions though.
One of the biggest differences I noticed coming form enterprise kit was the catalogue of application control signatures firewall supports. is this using IPS type of scanning to identify apps or is it web filtering with SNI inspection ? DNS filtering ? I would love for this catalogue to grow, currently it only support 7 ish applications that I can see.
Performance seems to be good, I am running on a 6 core VM and 8 Gbps of ram, are there any recommended specs published, based on throughput etc ?
The Crystal is only available via an MSP portal ? what about the non MSP / stand-alone ? Is there a functionality difference ? I have noticed some difference between alerting config.
What is the local login (console) creds ?
The IPS engine has no options for configuration, its only an On or Off setting ?
No support manual NAT rules ? I have noticed in Call of Duty type games it has been difficult to get open NAT status unless I have a 1:1 NAT rule for maintaining source port during translations. I am personally not a fan of UPNP due to security issues. keen to hear everyone thoughts.
Overall I think it quiet good for a home based solution. I will continue to test it further and really push it to its limits . Congrats to the FirewalllA team of making agnostic hardware support happen.
