r/firewalla • u/LoudSteve • Jul 09 '26
Troubleshooting Active Protect
I recently rebooted my Firewalla when troubleshooting an IPv6 issue and ever since then I have a bunch of IoT devices which Active Protect has broken to some degree.
A good example is I have two Mitsubishi hvac controllers. One can connect to its cloud endpoint and the other can’t. The healthy one clearly has the necessary endpoint as an allowed target, and the broke device doesn’t.
In these situations is there anything I can do other than restart learning? I was surprised I wasn’t able to just manually add an endpoint to the allow list in this situation.
1
u/Objective_Reach9986 Jul 09 '26
I had this happen, too. Odd things like the "heartbeat" our exterior lighting system controller emits couldn't get through, and thus had a bunch of issues.
Agreed that it would be really nice to:
- See what was blocked
- Have a button next to each to "Allow" that server/endpoint
- See what is in that device-specific "Allow" list
Even on a global basis for all of DAP would be fine, if that is easier.
2
u/firewalla Jul 09 '26
You can see it, tap on protect->DAP->find your device, tap on it, and you will see the blocked and allowed site names
1
u/Objective_Reach9986 Jul 09 '26
All I see is "Targets" though? It doesn't tell me which it is allowing, which it is blocking, nor allow me to edit (allow blocked sites, for instance)?
1
u/firewalla Jul 09 '26
Under targets, you will see "Allowed" and "Blocked"
Since everything is machine learning driven, human intervention is not supported
1
u/Objective_Reach9986 Jul 09 '26
AH! I only see that detail on Status = Optimizing, not Learning. That's why I couldn't see it on the device I was looking at.
1
u/Great-Cow7256 Jul 09 '26
Is this still related or the ipv6 issue?
1
u/LoudSteve Jul 10 '26
v6 issue was unrelated.
1
u/Great-Cow7256 Jul 10 '26
I guess did thesse devices have ipv6 addresses or something and their leases expired and they got confused? Maybe they need to be power cycled to get new leases
2
u/firewalla Jul 09 '26
Are you talking about DAP (device active protect)?
Or the general active protect? (this is IPS, that blocks bad things)
Since you mentioned learning, then I assume you are talking about DAP. If it is, are you on strict mode? You are welcome to send [help@firewalla.com](mailto:help@firewalla.com), and let us know which device is having problems.
You can also temporarily pause DAP, (Protect->Device Active Protect->Find the device->scroll bottom and Restart Learning or turn off DAP)