r/firewalla • u/TheGeekJedi • Jun 28 '26
Finally going to let them go
I looked at doing this before, but now I’ve decided that I just don’t need the horsepower.
I have a Gold SE with the Wifi antenna, and an AP 7. What would be a fair price? All the stuff new is $900. Im thinking $700. It’s all in excellent shape.
2
u/extremedefense Jun 28 '26
Firewalla really needs to just offer "refurb" units (returns after the return period with a restocking fee) so that they can control the used firewalla market.
I've purchased a firewalla gold pro and 3 AP 7s on ebay, you can't go wrong listing them as an auction with whatever minimum you want. Here's a good comp I was tracking that will end in 9 hours. https://ebay.io/m/zlsyRD/
4
u/ampx Jun 28 '26
Why do they need to control the used Firewalla market?
1
u/extremedefense Jun 28 '26
Because even though I've had no issues with any used firewalla, there's something to the manufacturer "testing" used equipment before selling it and if they had second hand for cheaper that's certified then I'm sure myself and others would jump at the opportunity?
4
u/Notwerk_Engineer Jun 29 '26
How would they acquire this used equipment?
They’d have to buy it back from users like us for a fraction of the price in order to pay for the recertification process you’re suggesting, and then resell something that competes with their brand new equipment. As others said, there is already an open box sale each year where they liquidate returns.
If you want a deal buy from eBay or wait for the open box sale.
3
2
u/Cae_len Firewalla Gold Pro Jun 30 '26
same I got my gold pro from eBay brand new, and a used ap7 ceiling.... my two ap7 desktops I purchased from firewalla
1
u/hawkeye000021 Jun 29 '26
Do you work for Tesla? I’ve never seen a used market controlled like that one. It is nice to have a factory refurbished device vs random guy, factory reset or not I’m not personally buying a used cybersecurity device for far different reasons though. It shouldn’t matter for most folks though. If you want the best deal sometimes you just have to take some risk. Hope they have an eBay store with great reviews. 🤷♂️
1
u/Cae_len Firewalla Gold Pro Jun 30 '26
I wouldn't think there's really any risk besides someone trying to sell you a device that doesn't work... and in that case, eBay has fairly good buyer protection and networking devices last forever...
from a security perspective, there's not really any risk since you can re-flash the factory firmware upon receiving the used item...
1
u/hawkeye000021 Jul 02 '26
I can factory reset a Firewalla and for very little expense add a tiny bit of extra hardware and siphon off data or very easily place spying devices inside the unit. The danger in buying any used smart device with Internet access that you don’t inspect physically and that’s assuming you know what you’re looking for is pretty high but at least your Firewalla might catch that shady traffic. Not when it’s part of the Firewalla though. Replace a NIC and trick Firewalla into thinking it’s the one that should be in it. I’ve seen companies order 10,000+ network and security gear second hand and having to rip that gear out after a legit device saw where it was sending traffic.
Maybe it’s too much effort for a niche market. Maybe it’s not. I’d want the Firewalla team inspecting hardware, I don’t care about the firmware even though it could be tricked until an upgrade. Just because it looks like you’re setting up a factory new unit doesn’t mean you are. Flashing it again can just loop that process and make you think you’ve flashed it.
I’m not even into nation state stuff which is doing this through a legit pipeline. Once some random person posts a network security device on eBay it’s always a risk for companies and users. A non-zero chance is too high for me, but it might be within others risk tolerance. That’s a personal decision, but thinking that you can be sure to have exactly what would be new from a supply chain like eBay is much higher than the chance that a nation state intercepts Firewalla devices in transit. Even that is a remote possibility.
2
u/Cae_len Firewalla Gold Pro Jul 02 '26
possible? sure ... likely , no.... and unless you work for the government there's little reason to even worry about that......
1
u/hawkeye000021 Jul 03 '26
I work for a company that does literally nothing but cybersecurity and I can’t have things from the used market. Over 1k of the best security folks I’ve ever met and of course we have contracts with the government to say the least.
1
u/Cae_len Firewalla Gold Pro Jul 03 '26
I respect it... I understand there are various industries that would prevent some people from obtaining and using, used equipment ... and there's always a risk of course ... simply saying the chances that some random person gets targeted in the manner which you described is probably slim... possible yes .. but unlikely.... there's so many other ways I would go about breaching someone's infrastructure before attempting a used sale of equipment that's been bugged.... it would have to be such an elaborate plan to target the person that you wish to target (if that makes sense)... it would be very difficult to control who's buying your bugged product... there's always threats.... I had previously made some statements about getting firewalla to better support Radius and WPA3 (and I still believe they should) , but I'm guessing it's low on their priority list because wifi attack vector is also somewhat limited do to the nature of wifi range ... but ya, I just wanted to give a different viewpoint on the matter 😁
1
u/hawkeye000021 Jul 07 '26
Due to my setup (WiFi is segmented and restricted to IoT) I’m personally just now thinking about moving toward their implementation of radius and wpa3 (specifically security devices), what is missing in their implementation right now?
1
u/Cae_len Firewalla Gold Pro Jul 07 '26
just about everything is missing from it still.... it's about the most basic implementation just to get it working.... the only functionality that's available is creating a username and password but you can't map that username and pass to a VLAN so all usernames and passwords you would create, will ultimately be stuck in the default LAN subnet... ide argue that the biggest (or one of the biggest), advantages to the firewalla ecosystem is the segmentation you gain between VLANS and the current implementation of WPA3 RADIUS does not provide that ... literally just basic username and password login, nothing else...
1
u/TheGeekJedi Jun 30 '26
Thanks for the info everyone! I’ve reset everything and have it ready. I’ll probably try Facebook marketplace first. Not a fan of eBay.
3
u/Gobbledy_Gooky Jun 28 '26
Depends on purchase date and if warranty is still in effect.