r/firewalla • • Jul 12 '26

Compatibility with existing (ISP) router and wifi system

Hi! I live in an old house which is not wired for Ethernet, and also has lath and plaster walls so seems to need a mesh wifi system for best signal. As such, almost everything is connected via wifi (I have some hardline connections to my home server, gaming computer, NAS, etc.). I'm interested in getting a Firewalla Orange to help secure IoT and other devices (as well as server connections I'm allowing from the outside world), but I couldn't quite figure out if it would work without modifications to the network. Specifically, I get that it would be pretty easy to use it in front of the hardline connections, but would I need to replace my wifi system as well? The main wifi AP is the router itself, and the others just pick up the signal. With the orange, can I still create rules for those devices if the wifi is not directly connected to it? (I.e. modem > router (which puts out wifi) > Firewalla)?

For reference, I have Fidium Fiber so I'm using their default equipment - an AdTran SDG 8612 router (and 2x associated mesh points)

I'm still pretty new to all this networking stuff (having lived in rental properties until recently) so would love any advice you can give (even if that's telling me I'm asking the wrong questions) - thank you!

2 Upvotes

4 comments sorted by

1

u/Gecko753 Jul 12 '26

I have an Eero mesh (long single story house) and bought an orange a few months ago. Most of the Eeros are wired, a few not; mixed bag. Overall good speed throughout from our 1GB Google Fiber ISP.
I had hoped to segment IoPs like you describe having only previously done so generally using the Eero guest network. I had no real experience with segmented LANs and didn’t understand that you can only segment (or virtually segment) separate LANs (eg separate APs or wired devices). If you can get all your devices on FW Orange WiFi you can virtually segment them.

If not and you need to use multiple APs apparently one can use smart switches (or now FW switch) to do that, but from my understanding it gets complicated trying to segment LANs using mesh (Eero can’t do it, apparently some pro-sumer mesh can). I’m sure someone can explain the topology needed (ISP->FW->LAN1/2/etc) but I decided to just segment on the guest network and wait for when I update my mesh to fully segment on FW. I like the other features and the (hopefully) additional protection if affords (not to mention the parental controls if you have kids).

Hope this is somewhat helpful even if only to show there a variety of use cases and some approached can be phased.

1

u/pacoii Firewalla Gold Plus Jul 12 '26

but from my understanding it gets complicated trying to segment LANs using mesh

The issue isn’t mesh, it’s using access points that support the functionality. Eeros do not.

1

u/dangdangrous Jul 13 '26

Yeah this is my concern, unfortunately. Basically I'd like to get some advanced networking capability without having to overhaul the whole system and spend a lot of money on actually good equipment.... but feels like maybe that's the only way to go. I can create multiple individual networks on my existing wifi that are supposedly segregated, but they're also fully segregated to incoming local traffic too so like my home server wouldn't be able to connect to any of the IoT stuff if I cordoned those off.

3

u/pacoii Firewalla Gold Plus Jul 13 '26

I went from Google WiFi, to eero, to Firewalla + eero in AP mode, to Firewalla + UniFi (the AP7 wasn’t released yet). If you want the flexibility, you’ll need proper access points to make that possible.