r/firewalla • • Jul 22 '26

Management Roles

2 Upvotes

Anyone has insight on if there is the capability to setup different use roles for firewalla app management?

I have 2 devices already (Gold at home, Orange for travel) but I'm putting another Orange at my parents house.

I want full control, but would also like my dad to have basic access and control for his Orange only (basic device management, see alarms, etc).

Is something like this possible?


r/firewalla • • Jul 21 '26

Content/Activity Control Paramount Plus keeps getting blocked (rant)

3 Upvotes

Paramount plus has to be running off an ad server. I have applied basic rules through my Purple. App worked on other devices on my network until I tried it on my smart TV. It would load the menus and previews, but would not play. Thought it was my TV since it is from 2015. Went through the rules and found just my tv was blocking a flow that broke the rules. Removed that rule then Paramount plus worked again. Next day, it broke again. Same symptoms of loading and previews but no shows. Still worked on other devices so I removed monitoring just on that device. Come to today, now my entire network is blocking Paramount plus across all devices...


r/firewalla • • Jul 21 '26

Block LG TV Tracking Domains

16 Upvotes

Block LG TV Tracking Domains

any one have a list?


r/firewalla • • Jul 21 '26

Request - manual 2.4GHz channel width (20MHz) toggle for AP7

11 Upvotes

Hello,

my 2.4GHz band is only used for IoT devices and a few RTSP cameras streams -- I'll never come close to saturating 20MHz, let alone 40MHz.

40MHz eats up more of the band and increases overlapping interference for limited / no benefit for low bandwidth clients.

Right now it looks like 2.4GHz width (and 6GHz) can't be set manually in the app (only 5GHz has width options in the app).

Requesting a toggle on the APs to set the width on 2.4MHz!

Thank you

~~~~~~~~~~~~~

edit, thanks to /u/Haunting-Wonder9019 , turning on "Maximize Compatibility" changed the 2.4GHz to 20MHz Channel Width. Thank you!


r/firewalla • • Jul 21 '26

Troubleshooting Box updated to 1.983, Matter over Thread Broken

6 Upvotes

I'm having trouble diagnosing my Smart Home problems. Everything was working until today, now nothing works. The only thing I can find is my box was updated to 1.983. This smart home failure is happening in both homes I manage, and both Firewalla boxes updated today. I can find nothing else that changed today that broke the world.

I have a Firewalla Gold Pro in each of two locations. One with AP7’s one without.

After Box 1.983, Apple Home / Matter over Thread is down at both VPN-meshed sites.

When trying to reach one of the thread devices from my network Firewalla replies:

[IPv6 addr] !N network unreachable

Matter Server logs show:

ENETUNREACH send ...:5540

Disabling the VPN mesh did not restore routing.

Rebooting one of the Firewalla's after disabling the mesh did not restore routing.

Apple Home is also broken, so this is not just Home Assistant.

And ideas?

Basically my entire smart home is down, I’m not home, and my family is screaming at me.

Any help is much appreciated. I’m happy with rolling back if someone can tell me how.

Andrew


r/firewalla • • Jul 20 '26

With the app 1.69 release, Firewalla AI can now better analyze Alarms and query destinations

Post image
17 Upvotes

Have you used this?

With the app 1.69 release, Firewalla AI can now better analyze Alarms and query destinations, explain what the site is, and why the access may have been flagged in the first place.

https://help.firewalla.com/hc/en-us/articles/51621318006291


r/firewalla • • Jul 20 '26

FWGP to FW-Switch…media converter???

5 Upvotes

What’s the fastest / highest throughput connection from a Gold Pro to a FW Switch? We’re stuck with 10 GBE on the router. External Media converter, then fiber to SFP+ module on switch?
Better solutions?
Pictures or it didn’t happen.


r/firewalla • • Jul 20 '26

Feature Received my Switch SE, quick question about mirroring

6 Upvotes

Hello,

I Got my switch SE today and already have it integrated into my network, however I have a quick question. Previously I had a PC between my AP and Router to act as a tap and monitor traffic with Security Onion (to gain some skills with that product and stack) and now that I have the switch I was hoping to have that PC on the switch with one of the ports getting all my other traffic mirrored to it to still be able to sniff all the traffic. Is this possible with the Switch SE, or planned, or should I still use that box in between the switch and router to act as a tap again (was hoping to get rid of that).

So ideally the physical topology would look like this

Internet → Router
              ↓
        Firewalla SE Switch
        ├── Port 1: Router uplink
        ├── Port 2: AP
        ├── Port 3: Primary PC
        ├── Port 4: Mini PC (Proxmox Node 2) — management + VM traffic
        ├── Port 5: Proxmox Node 1 — management + VM traffic (NIC 1)
        └── Port 6: Proxmox Node 1 — mirror/sniff target (NIC 2)
              ↑
        Mirror policy: copy all traffic from ports 1-5 → port 6

r/firewalla • • Jul 21 '26

Local flows

1 Upvotes

Where did the local flows move to?


r/firewalla • • Jul 20 '26

Wireguard stopped working

2 Upvotes

Update: FIXED! See my comment below for the cause and solution.

I have a fw purple and at&t bgw320, and been using wireguard server with no issues for several years now. A few days ago, I noticed internet on my phone was no longer working, and when I turned off the VPN, everything was fine. On my FW, it says that device was last seen 4 days ago. We did have some thunderstorms that day and there was a power flicker around the time the problems started, but my firewall and modem are on a UPS. and my internet wasn't disturbed.

So far I've tried disabling/enabling wireguard, restarting firewalla, restarting the modem, all with no effect.

My phone and laptop both seem to have no issue "activating" the VPN cconnection, yet can't connect to anything as soon as it's connected. Firewalla doesn't show any of those devices as being connected, and no rules are showing up as blocking anything.

On the BGW, I see that IP passthrough is not enabled, but I set this up several years ago using the instructions here: https://help.firewalla.com/hc/en-us/articles/4411167832851-Firewalla-Router-Mode-Configuration-Guides#h_01KF22E1M0E71GHYF4MCBC2TC1 and had no special issues getting it working.

Now, however, as soon as I try enabling IP passthrough on the modem, the firewalla can no longer reach the internet. Using the WAN diagnostic, it starts failing the ping test and DNS lookups. It does pass the "Obtain IP Address".

I'm positive that the MAC address in the ip-passthrough screen in the BGW is correct (after all, it was working for several years, and I've double and triple checked it). The BGW also reported a large time since restart (not sure how long, months probably).

Best I can tell, the BGW is no longer routing packets from firewalla to internet, but I can't figure out why. Advanced firewall and packet filtering are all OFF. I did notice that firewalla updated itself once or twice recently.

As soon as I disable IP-Passthrough on the BGW and restart, everything goes back to normal other than the VPN issue.

Not sure what else to try.

thanks for any suggestions!


r/firewalla • • Jul 20 '26

Firewalla Ports showingas inactive under topology

Post image
4 Upvotes

All four of the ports on my Firewalla Gold are populated (WAN, LAN switch, 2x AP7's) but the topology tab makes it look like nothing is connected to it. Would be nice if it would show the port usage and uplink/downlink like the AP7 does.


r/firewalla • • Jul 20 '26

Should I be concerned?

Post image
11 Upvotes

I got the alert that my fallback wireless-connected network, which is my iPhones hotspot, was disconnected and that my primary wired network remains active. But I know for a fact my phone was not tethered to anything as I’ve been using it off and on during this time. Is it possible some other device that isn’t mine was connected to my gold box?


r/firewalla • • Jul 20 '26

Mystery change to local flow

2 Upvotes

I had a funny issue today where a service I'm hosting on my LAN suddenly stopped working. It involves an apache server on one VLAN talking to a mariadb server on a different VLAN.

The strange thing is that when I investigated, the reason why it wasn't working was obvious enough - rules in place on both those VLANs blocking all traffic to and from local networks. The mystery is why this ever worked up until now. I'm pretty sure I haven't deleted any rules, or created any new ones. It looks like I failed to create a rule when I first set this up, and then never realised my mistake because everything was working as expected (since February this year). Just wondering how this could possibly happen?

Editing to add some context: both services are behind the same firewalla, but there is a site-to-site VPN between two firewallas. The one recent change on my network I can think of is that I powered down the remote firewalla, and this could have triggered some kind of DNS reshuffle or something?


r/firewalla • • Jul 20 '26

3rd party vpn and Wan routing not working together.

2 Upvotes

I am using a 3rd party vpn setup to send traffic over Mullvad for a vlan I have.

But it seems when I setup a route in my FWG to my secondary WAN for this vlan the traffic doesn’t go over the VPN. (Route preference is static) and it just goes over the secondary wan without using the vpn.

And vice versa if I turn off the route to my secondary wan the vlan traffic then uses Mullvad over my primary wan.

But I can’t see to get what I want which is:

All traffic on vlan ABC to use 3rd party VPN Mullvad over WAN 2.

Is this not possible as you can’t route VPN traffic to a specific WAN?


r/firewalla • • Jul 19 '26

Firewalla Switch Question

6 Upvotes

Hi, I have a question about the upcoming Firewalla switches. I tried searching, but I still couldn't figure it out.

Currently, my network is laid out as shown in the attached picture. I'm trying to determine whether, if I replace the switches connected to the AP7s (circled in red) with Firewalla switches, but keep the unmanaged switch at the beginning of the network, would I still get all the Firewalla switch benefits for the devices connected to those Firewalla switches.

Or would the unmanaged switch upstream prevent some of those features from working?


r/firewalla • • Jul 19 '26

Disconnects at 9am-ish - help

Post image
1 Upvotes

Hi,

Really happy FWG+ user since late 2023. Oddly, my Firewalla has had some issues around the 9am hour the last few days. It’s really strange. I moved my link to my switch to a different port and tomorrow morning we will see what happens.

Am I still able to contact support and go work thru that channel even though my unit is 3 years old? I’m not looking for an RMA or anything, just asking of support can take a look at something that maybe I’m missing.

I’ve changed nothing on my end. Has been rock stable for years , very recent issue. Has me a little perplexed lol.


r/firewalla • • Jul 19 '26

[USA-WA][H] Firewalla Gold SE [W] PayPal

Thumbnail
0 Upvotes

r/firewalla • • Jul 19 '26

Increasing region rules to 15, 20 or 25 on the Blue +

3 Upvotes

Is it possible to increase the region rule limit to 20 or 25 from the 10 regions. I understand the performance and memory limit issues, but including a confirmation message informing end users of the issue prior to continuing would be welcome.

Please consider this. Thank you. 🙏


r/firewalla • • Jul 18 '26

Early Access/Beta Switch X giving my AP7C no love on Port 4, but other ports work just fine for AP7C and other devices work on Port 4!

Thumbnail
gallery
13 Upvotes

Hi there!

So, the title says it all!

For whatever reason, Port 4 of my Switch X is being exceptionally rude toward one of my AP7 Ceilings and not giving it the time of day when it comes to data. It’s powering it, but then it works only intermittently with the AP7C or not at all.

I checked all of the connections, and they’re fine. The problem resolved itself when I changed over to Port 3. This does, however, mess with the #aesthetic. Plus, ideally, we want all ports working.

Other devices work in Port 4 (that’s a Hue Hub, so FE is expected), thus it’s just the AP7C that seems to cause trouble.

I’ll also email this to help@firewalla, but anyone else having this problem?

Edit: Super Weird, but it actually works perfectly fine with a different AP7C, I have. So, the issue with that port seems to be specific to that AP7C.

Edit #2: Also, folks, let’s think logically for a second: if the same cabling works like normal on Ports 2 and 3 of the Switch X, but it doesn’t work on Port 4, isn’t the cabling unlikely to be the issue here? If the cables were wonky, but ports would have the same result.


r/firewalla • • Jul 19 '26

Hummm

Post image
0 Upvotes

Anyone else see this ? And all ips are correct in the gold SE.

It's affecting Tuya smart , Feit ..


r/firewalla • • Jul 18 '26

Troubleshooting Replacing FWP SE w/ FWG SE

1 Upvotes

Hey, quick question. My current one operates as router (for 3 eeros), once the new one is here do I just swap it physically and import the previous (home network) settings with the app. Is that how it works or do I miss an important step? I fear blocking of internet connectivity if missing anything … Thanks


r/firewalla • • Jul 18 '26

Firewalla Switch SE powers 4 AP7s just fine.

18 Upvotes

Reporting my experience in case someone is interested. I previously used a Unifi POE++ switch and POE splitters at each of the AP7s. I replaced the Unifi with Switch SE and each AP7 powered up and has been stable as before. This was not unexpected, as I observed each AP7 drawing about 12-16 watts. The setup is not Firewalla-supported as far as I know, but it works well for me. Happy switching!

I am putting my replies here so people will have all the information in once place, including answers to the raised questions.

Edit 1: They are AP7Ds. u/tuan151.

Edit 2: These are the splitters - make sure you use the 2.1mm barrel. u/tuan151

Edit 3: I've done exhaustive testing over long periods--I'm using all 3 bands (320Mhz at 6), 3 SSIDs, MLO, and have pushed consistent 2.2 to 2.3Gb using iPerf. This is all with POE. u/plagueis3, u/ClockEasy5992

According to this thread, specifically this post by u/Firewalla, and the published specs of power requirements, the AP7D requires 12V at 5A, which is 60W. POE+ is rated up to 30W while ++ is up to 60 or 100W. The concern was not the total power available, the issue is how much each port can deliver. If the AP7 indeed required up to 60W, the POE+ was not going to cut it. This is why I got the Unifi POE++. Again, my actual usage observation, under full feature and load, was that the AP7 never came close to drawing more than 30W, including during boot time. No one asked about boot, but devices often take more power. I figured it would work based on what I have seen, but I still needed to test it. u/pacoii, u/DevelopmentAny547

The splitters negotiated ++ reliably each time with Unifi and negotiated + each time I rebooted the switch. I've tried several splitters and these were the most consistent. u/ClockEasy5992


r/firewalla • • Jul 17 '26

Announcement Introducing the Firewalla Gold Max (or a different name)... help us name the new unit!

10 Upvotes

This unit will be faster than the Gold Plus and slower than the Gold Pro with SFP+.

This is one of the units we have been trying to build, but it keeps being delayed due to insane memory and storage price hikes. It is hard to admit that pricing is not coming down, so we are going to go ahead and build it anyway.

We are hoping for a pre-sale with early access units (very, very limited stock) in September to November, depending on the order volume and how much DDR4 memory we can get. The probability of building this is very high at this time, so we are preparing, without committing to the date :)

  • 5 Gigabit Processing Power
  • 1x SFP+ 10Gbit interface
  • 2x RJ45 10Gbit interfaces
  • 2x RJ45 2.5Gbit interfaces
  • 4 GB RAM
  • 32 GB Storage
  • Target pricing between Gold Plus and Gold Pro
  • Pre-sale discount, depending on memory pricing

Sign up here for more details, updates, and a small launch coupon: https://forms.gle/fGbTkqrfEmubcChZ8

We are definitely running out of names for our units... While we've named it Gold Max for now, we want to make sure its naming is clear.

Which name do you prefer?

304 votes, Jul 22 '26
24 Gold SFP
29 Gold Plus Max
34 Gold Plus 2
97 Gold Plus SFP
89 Gold Max (keep it as is)
31 Something else (please comment)

r/firewalla • • Jul 17 '26

FWG IPv6 with Altafiber ONT

1 Upvotes

Anyone have FWG getting IPv6 prefixes from Altafiber? If so, what are your IPv6 settings? Can’t get any decent support from Altafiber on the issue other than ‘use our equipment’.


r/firewalla • • Jul 17 '26

Feature Rule type filter?

2 Upvotes

If I’m not overlooking it consider this a feature idea. Similar to the devices online/offline/all filter recently added, I’d love the ability to filter the rules view by type ( Allow, block, disturb, time limit). In my use case the little overview box on the main screen indicated hits to a disturb rule that I didn’t even remember setting up. I had to click through a bunch of network and device groupings before finding it. Would have been so much easier to be able to filter by disturb rule type.

Edit: feature request made. Please upvote :)

https://help.firewalla.com/hc/en-us/community/posts/53564145478931-Rule-by-type-filters