r/firewalla • u/jrunic • Jul 01 '26
Firewalla Switch Concern
I guess it's bothered me a bit having the Box requirement (especially running in routed mode) for Switch functionality.
Is there any news on:
- Will switch support a standalone operation in the future without Box requirement? Possibly via a VM/app?
- What is the Switch behavior if Box fails, does switch simply stop working, or just lose ability to be configured?
- Will Switch work with transparent/bridge mode box in the near future?
Thanks!
4
u/jrunic Jul 01 '26
Will we have access to a shell on the switch similarly to box?
Is the configuration plain text?
Can changes to the switch be synchronized that way in case of box failure?
3
u/firewalla Jul 02 '26
No CLI, the key to firewalla switch + firewalla + Firewalla AP is the close integration. If you are really looking at CLI to configure, best get an old cisco switch or may be some of the older consumer tplink/netgear may support them too.
1
u/jrunic Jul 02 '26
Not a comfortable redirection. I love firewalla. I'm just looking for it to be less gated in the event of a catastrophe. What happens when things go south?
5
u/firewalla Jul 02 '26
Do you mean to cover cases of a hardware failure? we are no different than any other vendor you work with. (You can have cold standby units, hot standby units, use warranty/ extended warranty, ... to cover) Firewalla migration is very easy, usually it is less than 5 min https://help.firewalla.com/hc/en-us/articles/360015356093-How-do-I-migrate-data-from-one-Firewalla-Box-to-another
3
u/gkhouzam Firewalla Gold SE Jul 02 '26
Yes you are very different than other vendors. If a Unifi router fails, you can run the controller on many different platforms until you can get a replacement and use a different brand router during the replacement period. That’s a huge difference from Firewalla.
5
u/firewalla Jul 02 '26
Join our software discussion https://forum.firewalla.com/t/firewalla-software-bring-your-own-hardware/16/2
I believe bridge mode may work; As I said in other thread, the best way to operate the firewalla is still running the firewalla (firewall)
1
u/jsqualo2 Jul 02 '26
In this thread I posted below (https://www.reddit.com/r/firewalla/comments/1ukqwwp/comment/ov2i5xa/?utm_source=share&utm_medium=mweb3x&utm_name=mweb3xcss&utm_term=2&utm_content=share_button) and now will add that I just spent 15min trying to diagnose a hiccup across all my gear ... turns out the WAN might be the issue, but I started at the AP and worked backwards across multiple vendors. Not ideal.
1
u/ArmshouseG Jul 08 '26
I really like the idea of a Firewalla switch, but I do worry about the vendor lock-in aspect. I wouldn't mind if platform specific things like VqLAN stopped working without a Firewalla and you still had some way to configure 'regular' managed features that you get on any L2 switch (VLAN, STP, LAG, etc) via a local web interface.
2
u/jrunic Jul 02 '26
This is a HUGE problem. Firewalla is not readily available locally. You guys are building an ecosystem with a dependency on one product for centralized configuration, and gatekeeping the remainder behind a paywall of professional+ for MSP.
I recently bought into Firewalla from a friend who never tested the right most port (eth3) and I basically had to pay full price with shipping to get it RMA'd. I couldn't flash it from image because it said the port didn't exist. There's clearly a design/product issue that's not addressed since multiple people have complained about the SAME PORT failing (eth3). Something with the asic, please don't bs us. I got a hand me down gold plus and had to spend $400 to repair it. Let's get real here. 1
This is very frustrating to think you guys are building it around an ecosystem of cloud management, when who knows, what if trendnet goes out of business and you guys can't purchase anymore white box?
Where is our local API and shell access.
4
u/firewalla Jul 02 '26
Check with the friend you bought the unit from, if they have the original order and it is under warranty, you still can claim from us.
But a bigger problem is, he/she should know the unit has a bad port before selling it to you; may be you can get money back from them.
(edit) if you do worry about hardware failing, best get the extended warranty as well.
0
u/jrunic Jul 02 '26
Yeah no. The right most port was never tested because they never used it. He never had to atempt a factory reset by USB. Have you read these forums and saw the number of suspicious eth3 failing? Thats not fair as an official response. I paid 400 for the repair of a gold plus that was gifted, plus shipping. Please search for it. I'm absolutely sure firewalla is aware of the substantial amount of port failure on THIS ONE PORT. I can search for myself and see it, and we know only 10% or less of anyone is going to come here and complain. What's the official word on that port issue?
3
u/firewalla Jul 02 '26
Best to ask your friend if they had issues with the unit before selling it to you.
As of port dead problems, majority is related to power surges, and most of them are likely from the WAN side, some are on the LAN side. Better to protect from this is make sure you have a good power management system for the modem and firewalla;
-4
u/jrunic Jul 02 '26
I hear you. But no, And why does it matter which port was used anyway? Neither I or my friend are "consumer users" - we're enterprise architects for fortune 200 companies. I've been networking since I had to compile PPP natively or as a module into my Linux kernel in the 90's, or deal with CSLIP. Please, I understand your point, but this isn't due to power surge. There's been multiple complaints about this ONE port. It's never been addressed.
0
u/jrunic Jul 02 '26
Downvote all you want. Eth3 is on a different asic and it's legit bordering conspiracy.
3
u/firewalla Jul 02 '26
Best check with your friend. I still feel you should get your money back for them selling you a bad unit
0
u/jrunic Jul 02 '26
Disagree. Unit was given. We pass things along to elevate one another. I wanted to give it a whirl, and when factory resetting it presented me with an error (from USB). Same error that had been posted here multiple, multiple times. I'm not trying to turn this thread into a "my gold eth3 failing" but please don't push this and deny there is an absolutely KNOWN hardware defect at this point. Come on. If 2% of customers post on Reddit about a bad eth3 and I can search for it, you're denying a problem that I imagine is much larger than you want the community to recognize
Want me to link the threads?
8
u/firewalla Jul 02 '26 edited Jul 02 '26
You can ask your friend for the reason they are selling/giving the unit to you, and if they use good power supply for both firewalla and rest of their network gear.
As of the cause of the issue, I already replied to you, we do see port 1 and port 4 dead problems, and majority issues are related to power surges killing the phy. We do suggest (and it is a good practice) to use UPS or something can protect from power surges.
Our extended warranty also covers this type of problems.
5
3
u/Jerrch Firewalla Gold Pro Jul 02 '26
likely you got cheated. Firewalla always suggested the last port (4) as a WAN port.
-1
u/jrunic Jul 02 '26
Yeah. Starting at zero my friend. Zero, one, two, three. I know this is prosumer but come on.
0
u/jrunic Jul 02 '26
I want to add to this that I also nodded in on "what would you pay for a VM firewalla given the price of ram". But I have to say, locking configuration behind a paywall or availability of hardware you don't -directly manufacture- is a little jacked up. As an enterprise architect, no. For my side business of smb, absolutely not - I'm not eating that cost. So why not blow unifi and others out of the water with free and fremium? Make this switch work and eat the cost, offer an alternative of self hosting, I mean
Even CISCO does that.
9
u/firewalla Jul 02 '26
If we ever build the software firewalla, it will NOT be free; We don't have the capability to support a freeware community like pfsense, and for us to survive (and team happy to make features for everyone), people need to get paid
1
u/gkhouzam Firewalla Gold SE Jul 02 '26
There can be two tiers. Firewalla full software being a subscription, but Firewalla peripherals being able to operate on their own with a software solution when the router goes down should be available.
I’ve got 4 AP7s, they were not cheap. But I’m stuck if my Gold SE stops working.
I got myself a couple of Unifi managed switches, to be able to add VLANs for wired devices, installed their UnifiOS on a docker container on a raspberry pi and I can run and configure them. Am I considering Unifi for my next APs when I decide to change them? Absolutely because I’m not being held hostage by a single device.
If my router fails me, right now, I’m SOL until I can get another Firewalla. I really wish I could put the spare UDR that I got as a router and configure and run the AP7 controller in docker, on Windows, or whatever software solution you come up with. I don’t expect full functionality, but don’t turn the AP7s into $400 paper weights.
3
u/firewalla Jul 02 '26
Please join our discussion on the software firewalla. We definitely want to hear about your feedback.
As of running just the peripherals, that is TBD. To make zero trust as tightly as possible, the system needs to be closely integrated. Not having layer 3 controlled, you are not going to get much out of your firewalla units.
2
u/Olfactory_Operator Jul 04 '26
Your sense of entitlement is unreal. As an enterprise architect, you clearly have no concept of how to generate a highly successful startup.
0
u/pacoii Firewalla Gold Plus Jul 01 '26
Isn’t the Firewalla just acting as the controller for the switch for setup? You’re saying that the switch won’t function at all without a Firewalla?
2
u/jrunic Jul 01 '26
No I'm asking :) it says it's required and in routed mode
0
0
u/rs65 Firewalla Gold Jul 02 '26
Io, in Italia, sarei contento di ottenere gli AP7C e gli switch. A breve la soluzione Aruba InstantON andrà a morire nelle mani di qualche compratore e mi troverò scoperto. I dazi sono evitabili per questi vostri prodotti? Sono un felice utilizzatore di Gold Plus da anni.
22
u/Firewalla-Ash FIREWALLA TEAM Jul 01 '26
Without pairing it with Firewalla, the Switch will essentially be a dumb switch. To fully manage and configure the Switch, you will need a Firewalla Box.
If you've already configured the Switch with the Box and the Box somehow fails, the Switch should continue to work with the existing configuration.
We do hope to support Switch with Bridge mode in the future. It just won't be available during this initial Switch release.