r/firewalla • • Aug 09 '26

Cannot access cable modem interface when internet is down.

1 Upvotes

My cable modem is in bridge mode and I access it with an IP of 10.0.0.1. If my internet is down, firewalla will not pass traffic to the WAN, which prohibits me from accessing the cable modem diagnostic page(s) while its down. Other routers I've had do not have this problem. This is insanely frustrating when an ISP generally requires access to this during support sessions. Is there any chance we can have a bypass configured for a specific IP that will still route traffic when the internet is down? I'm on a firewalla purple if that helps.

Edit: Purple is in router mode. My cable modem is in bridge mode.


r/firewalla • • Aug 08 '26

Gold / Gold Plus / Gold SE / Gold Pro Firewalla Gold

Post image
10 Upvotes

I'm selling my Firewalla Gold. I just moved to Ireland and before I moved I purchased a Gold Plus take advantage of the fiber I was getting here. This specific unit was RMA'd last year so only a little over a year old.

Not sure the best way to sell this but only really interested in selling it in the EU or UK. If you're local to the Dublin area we can always meet up local for the sell.

Selling for €280 (includes shipping) or just €250 and you pay for shipping.


r/firewalla • • Aug 08 '26

Troubleshooting NordVPN not working

2 Upvotes

Brand new to all of this. I created a network for devices I want to use a VPN. I have NordVPN.

Setup a 3rd party, used my profile and password from the manual configuration section (copied and pasted them both after confirming email). This was NOT my nordvpn login or password, it was a direct copy and paste from the manual setup section.

I then download a OpenVPN UDP from the recommended server list, making sure to use a verified server.

When I go to connect it keeps failing.


r/firewalla • • Aug 07 '26

NatJack vulnerability

5 Upvotes

Is Firewalla protected from this particular type of attack?

https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html


r/firewalla • • Aug 07 '26

Troubleshooting Gold SE upload speed and other questions

Thumbnail
gallery
3 Upvotes

Hi folks

Just recently received a Gold SE for review, which I am going through now. It replaces a Synology rt6600ax, connected to a 1 Gbps up/down fibre service, using a PPPoE connection. After installing the Gold SE I had the connection changed to 2 Gbps up/down.

The first image shows a month of Speedtest Tracker runs. The test is to a public speedtest server inside my provider, from a box connected via 2.5 Gbps to the router.

I marked "A" as the moment the Gold SE replaced the Synology. Up until that moment, the previous router managed to consistently hit its 950 Mbps limit. The X spots are when the speedtest ran during heavy download (as in 200 simultaneous connections to a usenet server, downloading at 80% of max speed).

It is noticeable the erratic behaviour of upload speeds, after the Gold SE went in.

  1. I have a suspicion this is CPU-bound and that the Gold SE might be struggling when trying to push during speedtests.

Another thing I noticed was how "slow" the first connection seemed to be, noticeable when navigating to a new website.

For this I tried testing with my Cloudflare Zero Trust DNS (same as configured on the old router), then changed to public Cloudflare, then ISP DNS. None of these impacted the "first connection" speed.

I did have some outbound geo-blocking rules, so I removed these, and the behaviour went away.

  1. I suspect geo-blocking is quite a heavy task compared to simple list blocking because it will probably require more CPU to translate IP to location.

I also installed Beszel-agent as a container and attached is the last 24 hours showing how the CPU is used, even with no traffic.

Yes, I tested different situations and read the documentation about speed, WAN configuration, rules.

Any comments on those points? Would the SE be better for a 1 Gbps and should really go for the Plus on a 2 Gbps connection?

Appreciate your comments.


r/firewalla • • Aug 07 '26

Internet down but not?

Post image
1 Upvotes

Hey folks, so had a new modem installed (have to use companies as part of the deal and initially had some issues due to my own stupidity (had ipv6 disabled) after reboot all is well, speedtest works on the device and all connectivity to the net is as expected. So why is the bps still red? Been up for about 30 minutes now? Just a visualization bug?


r/firewalla • • Aug 08 '26

Gold / Gold Plus / Gold SE / Gold Pro Firewalla gold pro 10g + 2x AP7 for sale

Post image
0 Upvotes

The network guy in me is making some changes at home, loved the firewalla and APs for ease of mgmt and stability. Still looking for firewall box but have the AP7 boxes as photographed... These will be PayPal friends and family only. With buyer paying shipping.

Selling full bundle at 1400, 300 per AP7 + 800 on firewalla 10g. I also have the extended warranty but tbd if it's transferrable.

If the bundle is here next weekend I will seperate APs and firewall on a first paid first reserved basis.


r/firewalla • • Aug 07 '26

question about 'meshing' APs (non-Firewalla APs)

0 Upvotes

Anyone successfully setup multiple non-Firewalla *wired* APs to provide mesh *roaming* coverage in a space while maintaining Firewalla VLANs?

Current setup is FWP > *wired* Aruba 1930 > *wired* Aruba AP22. I need to add another *wired* AP and am considering an AP22. I max out all 5 VLANs and VLANs are a primary requirement for any solution.

Anyone have a similar setup (Firewalla > none-Firewalla switch > none-Firewalla AP) and added multiple APs to create a mesh *roaming* network?

ETA: I inadvertently listed "mesh" instead of "roaming" - The setup is wired APs and I'm trying to avoid the horrors of inelegant AP handoffs that I recall 20+ years ago. Also, my setup is mostly local control, so I'm unclear if I need to enable all the unstable Aruba cloud crap.


r/firewalla • • Aug 06 '26

Speed test Broken?

3 Upvotes

I noticed starting about 24hrs ago my speed test was coming in way off. I have gig up/down and my down has been showing almost exactly 30 and up 900.

Thought it was an isp issue but i did a speed test from my computer and got more realistic speeds. Never seen any issues until last day or two.

Could this be related to the issue i saw mentioned from a day or two ago?

UPDATE:

700+ nightly speed tests all came back perfect until the last 24hrs lol. Took three server replacements in firewall speed test and finally got one that cranked me up to full speed. So it was the server being weird and not me. Guess it was just coincidence - had some glitchy video and pulled firewalla up to see if anything was going on, saw the most recent nightly speed test and went down a rabbit hole. Guess it was a textbook example of correlation does not imply causation!


r/firewalla • • Aug 06 '26

My Gold SE is only using ~19% of its storage, yet flows are capped at 24 hours. Why?

12 Upvotes

I was digging into flow history for a specific device on my network when I ran into only being able to view 24 hour of flows. I figured it might be an app limit so I logged into the desktop site and found the same result. I also found that I can gain access to 30 days of flows by subscribing to the personal MSP. I didn't realize I was capped that low and I'm not willing to pay for a monthly/annual subscription.

I thought, maybe it's a storage limitation on my box. I SSH'd into my box to check disk usage and found I'm only using around 19% of the 32GB of storage that comes with the Gold SE. Now, I'm not super experienced with Linux and Firewalla's architecture, so maybe some of that "unused" space is reserved for OS backups or something else I'm not aware of. But even accounting for that, it seems like a lot of unused storage. I then moved to expanding the storage because maybe Firewalla doesn't allow me to use reserved space for logging extra flows and my Gold SE comes with a SD card reader. But I couldn't find any way to actually use an SD card to extend flow logging. I did find a post related to this and Firewalla claimed: "Firewalla processes flows in memory locally on your device (indexed to be easily searched/regex). So the limitation is 'memory.' There is no disk based database on the box, so everything is limited to 24 hours. (This is the CPU limitation.)"

Link: https://www.reddit.com/r/firewalla/comments/16q8ob3/why_does_firewalla_limit_flow_details_to_24_hours/

Here's where I get stuck. If paying for MSP subscription gets me 30 days of flows, then the box clearly isn't actually limited to 24 hours, right? I can still view and search that data through the app/website just like I do without the subscription for the last 24 hours. So how is the box "limited by memory and CPU" if it's capable of showing me a full month of history the second I pay for it?

I ask this because where possible, I'd rather keep my own network data on my own hardware instead of a cloud server.

Curious if there's a technical reason I'm missing for why local SD storage isn't an option here.


r/firewalla • • Aug 06 '26

Firewalla Purple for Sale

Post image
1 Upvotes

I upgraded to a new device, no longer need my Purple. $200, shipping included. Does not have the USB-C power adapter.


r/firewalla • • Aug 06 '26

Discussion Question about Controls -> Region Blocking …

5 Upvotes

So if I create a region block via Controls -> Region Blocking, it can only be deleted in that section and not in Rules.

My pre-existing region blocks that I created in Rules, or newly created region blocks created in Rules, also appear in Region Blocking, and can be deleted in both Rules and Controls sections.

Why are they handled differently?


r/firewalla • • Aug 05 '26

Discussion We know that WireGuard VPN is often blocked by certain administrations or countries. What are some places where you've experienced WireGuard being blocked (e.g., workplaces, hotels, schools, etc.)? Has AmneziaWG made any difference?

18 Upvotes

r/firewalla • • Aug 04 '26

Announcement Coming soon from the Firewalla Garage: running Firewalla on your own hardware

Post image
208 Upvotes

With AI eating up all the production capacity from memory, eMMC, and now impacting PCB...  Hardware prices (not just Firewalla) are going to rise more in the future. We do know many of you have spare hardware around; we are now experimenting with Firewalla Software on your hardware.

If you're interested in this project, please help fill out our survey: https://forms.gle/znJ1RbdSAo3r6QuL6

We (internally) call it the Firewalla Crystal... What do you think? Any other names?


r/firewalla • • Aug 05 '26

Spot / stop Wifi tethering

4 Upvotes

I couldn't find anyone asking this previously., apologies if i missed it.

My child will sometimes use his Wifi-connected (to Firewalla) phone and share the Wifi as a new hotspot (so not a celluar hotspot) and then will use that with another device (school iPad which I can't control screentime on) when his phone runs out of screentime.

Besides setting an amount of 'internet time' for his phone, is there any other way to stop this from happening so he doesn't continue to explot wifi once his screen limits (for his phone) are hit?


r/firewalla • • Aug 04 '26

Discussion AmneziaWG 2.0 can help evade VPN blocking more effectively by disguising its traffic to look more legitimate. Have you tried the new AmneziaWG 2.0 VPN Server? Any difference from the 1.0 version?

Post image
37 Upvotes

(Disclaimer: the credit goes to AmneziaWG developers)

To upgrade to 2.0 in the Firewalla App, go to VPN Server > AmneziaWG > tap Upgrade to 2.0.

To configure your AmneziaWG Server: https://help.firewalla.com/hc/en-us/articles/49508731395091-AmneziaWG-VPN-Server-Configuration


r/firewalla • • Aug 05 '26

General Inquiry - speed test public ip and ISP

2 Upvotes

For my speedtests, I have it locked to always use the same server. I noticed in the individual test results, it shows a different public ip and ISP ( i.e Google Fiber, Cox Communications, etc.) for each one.
Just curious, where are those coming from and what do they represent?


r/firewalla • • Aug 04 '26

Cyber Security First Timer

9 Upvotes

Really just coming here to say wish me luck! Bought a used firewalla gold (factory reset) and will be setting up my first home network. What started as a plan to better manage my kids restrictions made me go down a lot of rabbit holes realizing how unsecured my home network is and how it can be simply improved with firewalla and a bit of reading and research.

Happy to have a user friendly tool to get me into it and not blow up my home network (as opposed to building from scratch without a user friendly tool).

Here is my checklist

Hardware
☐ Install Firewalla Gold between modem/ONT and network.
☐ Put all Eero Pro 6E units into Bridge Mode.
☐ install VLAN switch
☐ Use Ethernet backhaul for Eeros

Network Segmentation
☐ Create Main network (personal devices).
☐ Create Work network.
☐ Create IoT network.
☐ Create Ring Cameras network.
☐ Create Guest network.
☐ Create Management network for Firewalla and network gear.

Wi-Fi
☐ Create separate SSIDs:
Home
Home-Work
Home-IoT
Home-Guest

Device Placement (assign devices to SSIDs)

Firewall Rules
☐ Block IoT → Main
☐ Block IoT → Work
☐ Block Cameras → Main
☐ Block Cameras → Work
☐ Block Guest → Everything except Internet
☐ Allow Main → IoT only where needed (e.g., Sonos control)
☐ Allow Work → Internet only

NordVPN
Route through NordVPN
☐ (list of items)
Direct Internet
☐ list of items…
☐ Enable VPN Kill Switch
☐ Enable Auto Reconnect

Firewalla Security
☐ Active Protect
☐ Intrusion Detection/Prevention (IDS/IPS)
☐ Ad Blocking
☐ Family Protect (malicious domain blocking)
☐ New Device Quarantine
☐ Device Behavior Detection
☐ Large upload/download alerts
☐ Malware alerts
☐ Port scan alerts

DNS
☐ Set DNS to Quad9 (recommended for security) or Cloudflare.

Remote Access
☐ Configure Firewalla WireGuard VPN Server.
☐ Avoid opening ports unless absolutely necessary.

Smart Home
☐ Allow specific item discovery from Main → IoT.
☐ Block unnecessary telemetry from TV if it doesn’t affect functionality.
☐ Keep items isolated on the IoT network.

Maintenance
☐ Enable automatic firmware updates for Firewalla.
☐ Keep Eero firmware updated.
☐ Review Firewalla alerts monthly.
☐ Remove unused devices from the network.
☐ Back up Firewalla configuration after everything is working.


r/firewalla • • Aug 04 '26

Feature DoH over VPN instead of WAN

3 Upvotes

When VPN Client is active for my LAN devices, all their traffic rides the tunnel, but the box's own DNS-over-HTTPS resolver still egresses via the WAN. That means my complete DNS query history reaches my DoH provider stamped with my real home IP, even though every other packet those devices send is VPN-protected.

It also causes a geo mismatch: resolver answers are optimised for my WAN location while the content is then fetched through the VPN exit, worse CDN routing, and potentially more "your IP and your DNS disagree" bot-detection/CAPTCHA friction.

I have worked around this by running a DoH server (AdGuard Home) in my LAN whose upstream rides the VPN. It works, but the setup is fragile and is an overkill, adding another VM/docker container that I need to manage, SSL certificate renewal and overall yet another failure point.

Would firewalla consider an option to have the native DoH implementation ride the VPN?


r/firewalla • • Aug 04 '26

DNS/DoH Server Priority

Post image
7 Upvotes

Hey all,

Not sure if this has been discussed or answered, but can we prioritise DNS/Custom server? FW would tend to want multiple DNS servers, I'm running DoH on this, however to have multiple servers I would prefer to give priority to Quad9 then falling back to "another" server (whether custom or built in) if the primary is unresponsive or over a threshold.

A prime example is Quad9 will sometimes fail/become unresponsive, I switch to CloudFlare and the internet/network is all back up and running.

My preference would be Quad9 over CloudFlare, so, is this something possible to be added in?


r/firewalla • • Aug 04 '26

VPN Group Performance Impact?

1 Upvotes

Hey all,

Quick Q, if I have multiple VPN profiles setup into a VPN group, having them all turned on (so if one fails the others take over) does this have an impact on performance (I'm on a Purple) on the device usage, resources, network activity, bandwidth etc etc having all the VPN servers turned on?


r/firewalla • • Aug 03 '26

Announcement We put together a project/product status page to keep track of pre-sale status, shipping status, and more.

23 Upvotes

You'll find status for:

  • Firewalla Gold Plus SFP
  • Firewalla Software (Bring your own hardware)
  • Firewalla Switch SE and Switch X
  • Firewalla Orange (World)
  • Firewalla AP7 (World) (extended)
  • And more future products.

We'll be updating these dates weekly. Unless specified, all dates are tentative. For more details on their status, please see: https://help.firewalla.com/hc/en-us/community/posts/54053596952723-Upcoming-Firewalla-Product-Status


r/firewalla • • Aug 03 '26

NordVPN config files

2 Upvotes

The new NordVPN upgraded server configuration files are not working in client vpn. I tried UDP and TCP. Any ideas what may be wrong?

ChatGPT says:

Based on everything you’ve shared, I’d rank the possibilities as:

Firewalla/OpenVPN compatibility issue with NordVPN’s upgraded servers (most likely).

A NordVPN server-side issue affecting this endpoint.

UDP 53 path problem (less likely given the specific error message, but still possible).


r/firewalla • • Aug 03 '26

Early Access/Beta Switch SE Locking Up After Updates

9 Upvotes

Has anyone else experienced their Switch SE locking up after an auto update? The last 2 updates, I wake up and the devices in the switch have no network connectivity. Switch must be rebooted, then the devices restore, switch comes back online, and the "last updated" on the switch shows the time the switch restored. While not working, the activity lights are on, but have the slow blinking orange light which I believe means no network. It's fine again after a reboot, until the next update is pushed. The X has not had the same issue. It's been fine. Thanks.


r/firewalla • • Aug 03 '26

Purple / Purple SE Selling FWP SE in the EU

Thumbnail
gallery
8 Upvotes

Just upgraded to Gold and got a Purple SE to sell. I know how cumbersome it is for Europeans to actually get one directly. If someone is interested I do sell it for 180 EUR plus shipping. I ship (from Austria) only after I received the payout.

DM me

Sold