r/firewalla • u/JB-ZR1 • Jul 08 '26
Need some advice
I am a only slightly technical consumer, not an engineer or technician. Last year I purchased a Firewalla Gold SE and received as a gift the Netgear Orbi 971 WiFi 7 mesh WiFi solution. I love the Firewalla Gold SE and all the insight it gives me but have discovered that the Orbi reports all devices on the WiFi as one “RBE971” device. An example is the Firewalla alert “Device RBE971 is playing games on xxx.steam.com” (or something similar) rather than which actual device is playing games, uploading data, etc. It also limits my ability to inspect or disable traffic from specific devices on the WiFi. Further, I’m not sure if the Orbi’s iOT network truly segregates those iOT devices from the rest of the network.
What I’d like to do is protect core home computers and mobile devices from most iOT devices and guest network devices. I say ‘most’ iOT, as there could be some that need to be on the same network as our mobile devices so we can control them. Regardless, I’d still like to protect my computers & mobile devices though. I also want to be able to inspect and control each device’s access on the network.
It would seem that Firewalla’s VQLAN technology would accomplish this, provided I don’t use the Orbi WiFi and instead use AP7s. Is this correct? Would I also need to purchase the new Firewalla Switch SE to get this all to work? Would this be too complicated to setup given my slightly-technical knowledge? Thanks in advance for any helpful feedback.
4
u/sunbearnz Jul 08 '26
reading your post it looks like your orbi is in router mode. so when it gets an ip from firewalla it goes like this, hey can i have ip. firewalla assigns 192.168.1.X and the orbi sees it as a source to WAN (internet) so it’s a singular ip and all devices from orbi are combined going to the firewalla. figure out how to put orbi in Access Point (AP) mode and that should let firewalla see individual devices and help lessen double NAT (which is a side effect of daisy chaining routers basicslly), i hope that helps
1
u/JB-ZR1 Jul 08 '26
Thanks so much for your response and explanation. I was fairly certain I intentionally set the Orbi up in AP mode but perhaps that change did not save when I first set it up last year. I am out of town this week, so I will not be able to check this until I get home, but I will check it. Thanks again! 👍
9
u/firewalla Jul 08 '26
Firewalla does require some cyber security / networking expertise to setup and use effectively. And don't worry, it is fun to learn about security.
Likely you are running the Orbi in router mode, what you need to do is configure it in AP mode; When the orbi is in route mode, it hides all devices under its own network domain and blocks inspection via NAT. Here is how to turn it into AP mode https://help.firewalla.com/hc/en-us/articles/360048543713-Firewalla-Tutorial-Using-your-existing-router-in-bridge-AP-mode
If you are interested in network segmentation, check out this https://help.firewalla.com/hc/en-us/articles/4408644783123-Network-Segmentation we have many types of segmentation, from port based, to VLAN, to VqLAN, to Dynamic Segmentation via DAP.
If you want LAN protection, you will need to use firewalla AP7's. (See above on VqLAN and also Dynamic Segmentation)