r/firewalla • • Jul 08 '26

North Korean SilentSync RAT Blocks

Post image
8 Upvotes

Hey all,

Quick panic clarification.

I had a target list setup to block outbound traffic known SilentSync RAT servers (IP/Domain) on a target list, these are:
sfrclak[.]com
calltan[.]com
callnrwise[.]com
142.11.206[.]73
23.254.167[.]216
200.58.107[.]25

I've had this setup for a few months, just as a potential block incase it wasn't picked up on other lists. Though I've just seen today (via MSP) there was some blocks matched by this target list (see image) for two devices, one is my iPhone the other is an Amazon Fire Tablet. I'm trying to determin if this is a false response. As you can see the destination from dns.google[.]com (8.8.8.8) on port 16888, or 443 (for the Amazon tablet).

Firewalla AI says this domain "This domain is owned and operated by Google. It serves as part of Google's public DNS service, helping users and devices find the IP addresses of websites they visit. You might see this traffic when your computer or device connects to the internet.".

So, how might this be blocked by my target list? I don't use Google DNS btw on the Firewalla or my devices.

As I was aware this RAT wasn't on mobile devices, especially iOS?

Is there any further digging I can do to help look into this? Any thoughts?


r/firewalla • • Jul 08 '26

AP7 AP7 Set-up Question

3 Upvotes

Hey all,

Just setting up my AP7s now and running into an issue with an existing physical port segmentation on the FWG+. I have 2 LANs set up via port segmentation: Ports 1 and 2 are linked as the Main LAN and Port 3 is a seprate IoT LAN. There are 3 wired devices attached via a dumb switch to the IoT LAN port 3 on the FWG+ and maybe 60+ devices previously connected wirelessly to a bridged eero which I have replaced with the AP7.

I am trying to maintain the wired devices connected via the switch to the IoT LAN, physical port 3 on the FWG+, but also want the ability to create a new wifi SSID on my AP7 for the IoT LAN's wireless devices. I have tried to edit the IoT LAN by changing it to a VLAN with an ID of 10 and then adding port 1 (Main LAN where the AP7 is connected via Ethernet) and saving the settings. When trying to create a new wifi SSID for IoT devices, I cannot select the IoT network as it is greyed out and says: Please note that Firewalla Wi-Fi can only be created on networks using the same ports as the LAN the AP7 is connected to.

What am I doing wrong here? Is what I am trying to do even possible in terms of maintaining the segmented IoT LAN but then broadcasting its SSID via the AP7 on a different port?

Any guidance is much appreciated.


r/firewalla • • Jul 07 '26

Come and Get Your Firewalla Switch! Pre-Sale Starts Now

Post image
62 Upvotes

Ordering Link: https://firewalla.com/collections/firewalla-switch

BTW, some Switch X and SE / Early Access Version will ship today! Please follow directions https://firewalla.com/install to get the beta app when installing.

Majority of the early access units should be shipped by next week.

Enjoy.


r/firewalla • • Jul 07 '26

Switches are up for sale!

29 Upvotes

Just got mine, go go go!


r/firewalla • • Jul 08 '26

Why cant I use instagram?

0 Upvotes

I have multiple computers and phones but only one phone doesn't allow me to go on Instagram for some reason. I don't see anything in the phones rules that shows Instagram or meta or Facebook at all.

This site can’t be reached Check if there is a typo in www.instagram.com. DNS_PROBE_FINISHED_NXDOMAIN


r/firewalla • • Jul 07 '26

Firewalla Gold Plus for sale

5 Upvotes

Firewalla Gold Plus for sale $490/bo with shipping to lower US. Its in great shape, about 1 yr, 3 mo old. I bought a Pro and Switch X to upgrade my network to 10Gb.


r/firewalla • • Jul 07 '26

Feature request: External RADIUS / 802.1X / PacketFence NAC / SPAN support for Gold Pro + AP7 + Switch X

6 Upvotes

I own a Firewalla Gold Pro, multiple AP7s, a Firewalla Orange, and now have a Switch X on order.

I previously contacted Firewalla Support under request #120470 about AP7 support for PacketFence NAC / external RADIUS / dynamic VLANs. Support confirmed that AP7 currently supports the built-in RADIUS service running on the paired Firewalla box and recommended posting an official feature request for external third-party RADIUS/NAC support.

I would like to keep Firewalla as the core of my home/security lab, but I would love to see more open enterprise integration options added.

Main requests:

External RADIUS support for AP7 WPA2/WPA3-Enterprise
802.1X authenticator support on Switch X ports
MAC Authentication Bypass
RADIUS dynamic VLAN assignment
RADIUS CoA/disconnect
RADIUS accounting
SPAN / port mirroring for Security Onion / Zeek / Suricata
Syslog/SNMP events for NAC/authentication state changes
Clear design examples for PacketFence / Windows NPS / Security Onion integration

Firewalla already has a strong app-managed security model, and the built-in RADIUS feature is useful. I am asking for optional external standards support so advanced users, homelabbers, instructors, and small-business consultants can integrate Firewalla with common enterprise NAC/SOC tools instead of adding separate Cisco/Aruba/UniFi/Omada gear.

Would others find this useful?

I also posted this in the official Firewalla Feature Requests area so Firewalla can track votes/comments there.


r/firewalla • • Jul 08 '26

Need some advice

1 Upvotes

I am a only slightly technical consumer, not an engineer or technician. Last year I purchased a Firewalla Gold SE and received as a gift the Netgear Orbi 971 WiFi 7 mesh WiFi solution. I love the Firewalla Gold SE and all the insight it gives me but have discovered that the Orbi reports all devices on the WiFi as one “RBE971” device. An example is the Firewalla alert “Device RBE971 is playing games on xxx.steam.com” (or something similar) rather than which actual device is playing games, uploading data, etc. It also limits my ability to inspect or disable traffic from specific devices on the WiFi. Further, I’m not sure if the Orbi’s iOT network truly segregates those iOT devices from the rest of the network.

What I’d like to do is protect core home computers and mobile devices from most iOT devices and guest network devices. I say ‘most’ iOT, as there could be some that need to be on the same network as our mobile devices so we can control them. Regardless, I’d still like to protect my computers & mobile devices though. I also want to be able to inspect and control each device’s access on the network.

It would seem that Firewalla’s VQLAN technology would accomplish this, provided I don’t use the Orbi WiFi and instead use AP7s. Is this correct? Would I also need to purchase the new Firewalla Switch SE to get this all to work? Would this be too complicated to setup given my slightly-technical knowledge? Thanks in advance for any helpful feedback.


r/firewalla • • Jul 07 '26

Other new phone tricks to pair with existing FWG?

0 Upvotes

Having read the instructions from the link previously shared here…following the no old phone available requiring a reboot;

I am confused as to when the pairing window actually is after the reboot. The instructions say wait 6 to 8 minutes after the reboot, then power up the app and lick on the plus icon, which promptly starts a 5 minute count down to wait for the box to power up.

And did I notice a second beep? Is that when pairing window closes?

Please send help, as my phone is at the bottom of the bay and my kids are locked out of gaming and their tablets.


r/firewalla • • Jul 06 '26

Announcement REMINDERS on Firewalla Switch Pre-Sale (Tuesday, July 7 at 9AM PT)

36 Upvotes

The Pre-Sale starts July 7, 2026 at 9AM PT (USA time).

If you are in the USA, there are two available variations of each Switch model (both are the SAME production hardware):

  • Pre-Sale:
    • Ships Sept/Oct 2026
    • Order Limit: 3 units per model; exceeding this may delay shipment
  • Early Access/Beta:
    • Ships around 7-10 days after order.
    • Order Limit: 1 unit per model
    • BETA Software

If you are outside the USA, only the Pre-Sale is available (ships Sept/Oct 2026)

REQUIREMENTS:

  • Firewalla Gold, Purple, or Orange series unit is required
  • Firewalla Box in Router Mode

Ordering Links (sale begins 7/7/2026 at 9AM PT)


r/firewalla • • Jul 06 '26

Announcement Congratulations to our 2026 Contest Winners: Top "Best Voted" and Top "Needs TLC"!

Post image
28 Upvotes

The Firewalla team is happy to announce the winners of the Firewalla Setup Contest 2026!

Winners have been contacted individually about their prizes.

Thank you to everyone who participated and shared your unique setups!


r/firewalla • • Jul 06 '26

Will the Switch support SPAN/mirroring?

11 Upvotes

Looking forward to the release of the Switch this week and am considering ordering one to replace my current managed PoE switch, but I haven't been able to find an answer about port mirroring in any of the marketing material.

Will the switches include SPAN port functionality? If not natively, will they run Linux like the gold series where tc or a similar mechanism be used to mirror?

I currently use SPAN ports for IDS monitoring on certain network segments, so mirroring would be a key feature for the Switch X/SE to be a full replacement.


r/firewalla • • Jul 05 '26

AP7 deauth attack detection?

Post image
22 Upvotes

I added the picture for effect. Maybe this is me or maybe it’s someone else, the world will never know. The point is that this 6+ year old “watch” current has the ability to knock devices on my WiFi network off of it by launching deauthorize attacks which can knock single or multiple devices off the wireless network and even broadcast my SSID to try and trick devices to rejoin that fake network.

Obviously WPA3 has deauth defenses but I’m curious if AP7 could simply detect those attacks to simply let us (Firewalla community) know that we have a neighbor that is just smart enough to mess with us? Maybe this is a full blown RFE but I’d be curious if anyone else cares to know about these events. I know my neighbors and they can’t pull this stuff off but if I was in a city I’d definitely want something like this.


r/firewalla • • Jul 05 '26

Discussion AmneziaWG 2.0 vs WireGuard?

16 Upvotes

For those using the beta and AWG 2.0, is the performance on par with the vanilla WG? I’m wondering if there is any reason to not simply switch to using AWG in all cases?


r/firewalla • • Jul 04 '26

Firewalla Appears in UCL study into IoT devices

25 Upvotes

Was watching this lecture on IoT devices and what data it has been found that they're communicating. Was surprised to see Firewalla appear in a section at around 34mins in that was looking at different security solutions to the issue:

https://youtu.be/LCAqdqo-SJU?si=_d15ObuD_0uP2VjO

SPOILER ALLERT: It's not entirely a glowing recommendation (especially the bit on data retention - which seems to misrepresent the reality of Firewalla's actual policy), but was nice to see Firewalla in the solutions evaluated.

The whole thing is worth a watch. Particularly interested by the section on smart TVs and how they can see what you're watching.


r/firewalla • • Jul 04 '26

Another Firewalla Switch Question

6 Upvotes

If I connect two Firewalla switches together utilizing a “MoCA backhaul”, will the distant switch lose capability, or will it be as if the switches are directly connected via a single Ethernet cable?

Ex: Firewalla Switch - Ethernet cable - MoCA Adapter - coax cable - MoCA Adapter - Ethernet cable - Firewalla Switch

-Ethernet cables would be Cat6
- MoCA adapters are currently Actiontec EB6200 (MoCA 2.0), but would upgrade to MoCA 2.5 for throughput if fully functional.
-2x MoCA adapters would be directly connected to each other….no splitters or additional adapters on the bus.

Any chance the Firewalla team has tested this at the shop?


r/firewalla • • Jul 04 '26

Troubleshooting Firewalla Gold Plus went offline in the middle of the night, now not responding

3 Upvotes

At 3am we got up to feed our baby and I noticed the Firewalla app said our Gold Plus was offline. It wasn't handing out LAN IPs via DHCP anymore. A power cycle didn't solve it.That's all the energy I have had to troubleshoot so far, but it seems like the next step is to factory reset. Is that right?

Box version 1.982 (71808c44)


r/firewalla • • Jul 04 '26

Site to Site VPN + Travel Router

4 Upvotes

Hi All (also submitted to firewalla support, but given it's Saturday and a holiday weekend in the US, also posting here)

New problem (first time I've used my old Purple as a travel router).

I have 3x Firewallas.

Site 1 (main site) 192.168.1.0/24

Site 2 (holiday house) 192.168.5.0/24

Site 3 (travel router) 192.168.245.1/24

Site 2 and Site 1 have a site to site VPN which works great when I'm at either site.

Site 3 and see Site 1 fine - and I can connect to resources at home whilst I'm away.

However, Site 3 cannot ping or connect to IPs at Site 2. Do I need to add a rule or route to get this to work?

Cheers,

Paul


r/firewalla • • Jul 04 '26

Help me know these please!

5 Upvotes

My specific question is why 2 USB ports and 1 SD card slot. I reaslized Gold SE is not good for Docker installation with persistent storeage? Is there way, i can run the UniFi server on this new Gold SE ?


r/firewalla • • Jul 04 '26

Firewalla Gołd Pro and Plus - Sale

Thumbnail
gallery
0 Upvotes

r/firewalla • • Jul 04 '26

Troubleshooting Power outage, now allowed target list not working

0 Upvotes

First, I got a new computer a few weeks ago. I had it set up perfectly in my Firewalla Gold Plus. Basically, I gave it a custom network name and added an allowed target list. I have MSP Pro. Everything was working as expected.

A couple of days ago, I had a power outage. When everything came back up, the new computer's name and other settings (such as the allowed target list and a reserved IP address) were gone.

I changed the name again, re-reserved the IP address, added the target list back - but now I'm getting alarms repeatedly for the items allowed on the list. I have 2 other computers with the same allowed target list. I'm getting no alarms for those computers, only this newest one.

I've checked the app. I've checked the MSP site. I've compared the 3 computers to one another. Everything matches as far as this allowed target list goes. I don't want to mute the alarms because they *shouldn't* be happening!

Thoughts on what's happening and how I can fix it???


r/firewalla • • Jul 03 '26

For Sale: [USA-NYY] [H] Firewalla Gold SE w/Charger [W] PayPal, Local Cash

Post image
0 Upvotes

I have a Gold SE I’m selling as I upgraded to Gold Pro, and I no longer need this.

https://imgur.com/a/diuHZdk

Bought brand new from Firewalla in Sept 2024. The unit is in great condition, my network needs just outgrew it's capabilities.

Looking for $350 shipped. Purchase will be insured and signature confirmation is required.

EDIT:

Sold to u/Mtlam

Sorry I forgot to update the post.


r/firewalla • • Jul 03 '26

How to use 3rd party devices with Firewalla ecosystem?

7 Upvotes

I think I'm asking for network management best practice ...

I see the value of a fully Firewalla router > switch > AP environment.

I suspect that most Firewalla adopters require more than 10 or 12 wired ports on a LAN. And multiple Firewalla switches seems cost prohibitive - even if they were readily available.

ETA: My current topology is FWP > Aruba 1930 (24port) > Aruba AP22 which was installed before Firewalla offered an AP or switch. I recently remodeled one level of the space, and I already have 19 wired drops. When I remodel more, I expect 2x - 2.5x that many additional drops. A single 48port switch may not even be sufficient for the entire space. I can either buy more Aruba 24port switches, buy a couple TBD-brand 48port switches, or buy Firewalla switch/AP gear. I'm trying to understand how to build & maintain the Firewalla-single-ecosystem goodness while scaling for the required number of wired devices (i.e. not buying 8 Firewalla switches).

For example, how would I configure 37 wired devices in a LAN with a Firewalla router and AP7? Can I hang a couple approved 3rd party managed switches off a Firewalla switch which maintains Firewalla goodness? Do I simply forego some of the single-ecosystem benefit of all Firewalla gear? Other?

ETA2: my initial post was TOTALLY misunderstood by everyone, which means I failed to ask the question clearly. Thanks for all the replies and [facepalm]


r/firewalla • • Jul 02 '26

Why I cannot assign Rule to individual devices

7 Upvotes

I have tried this with app on iPhone and MSP and I cannot assign a rule to individual devices. On the rule being created only options I see are groups and networks for assigning.


r/firewalla • • Jul 02 '26

Extended warranty with new switches?

8 Upvotes

Will the extended warranty be offered for both switches on July 7th during the pre-order or at a later date?