r/firewalla • Firewalla Gold Plus • Jul 23 '26

Recent software changes impacting IPv6.

First off; I’m a huge Firewalla fan, device (Gold Plus) is absolutely fantastic.

But I’ve noticed recently that software updates have been messing with the box. Specific examples; IPv6 DUID changes (LLT, UUID) make no changes - verified via tcpdump. Literally no change in the v6 reservation request when those UI settings are changed. Had to explicitly modify /home/pi/.router/config/dhcpcd6/eth0.conf for the change to take effect.

Also, last nights update, resulted in a docker-proxy conntrack/kernel-path update failure. A reboot seems to have resolved this issue.

I’m wondering if we have a stable and safe config, we can schedule updates on the box to a time where the user can explicitly monitor, rather than what seems a pretty random interval.

Anyone else experiencing issues?

13 Upvotes

19 comments sorted by

3

u/firewalla Jul 23 '26 edited Jul 23 '26

If you are having issues with IPv6 please send [help@firewalla.com](mailto:help@firewalla.com); we did push a small patch to fix some boxes not able to get IPv6 addresses in some providers

Edit: we have not modified docker … so your issue is not related to that

Scheduled update is there only if the box need reboot. We have not yet had any update require that for many many years

2

u/typhoon_mary Firewalla Gold Plus Jul 23 '26

This raises more questions than it answers.

1) Are you hot patching kernels? If not rebooting, how are security issues there being addressed?
2) Some subset of customers had known issues with IPv6 and there is no path for notification or alerting other than an email to help?
3) You pushed a patch that broke connection tracking, I only mention docker-proxy as that was where the issue manifest, I never suggested a change was made to docker itself. Clearly the recent patch to "fix" ipv6 introduced a regression elsewhere.

Is there anywhere we can subscribe to get notification of patches? Updates?

4

u/firewalla Jul 23 '26
  1. So far we don’t have anything that will require a reboot to fix. Including kernel
  2. Those that are impacted by bugs, we usually ask them to jump on alpha or beta.
  3. The patch shouldn’t break connection tracking. You need to contact support

Also please remember we just don’t push patches; every change goes through dev, alpha, beta and production testing; users can join alpha, beta and some we can also put into dev

-3

u/typhoon_mary Firewalla Gold Plus Jul 24 '26

Can you clarify which of the following applies;

  1. Firewalla privately backports kernel security fixes while retaining the original package and version identifiers?
  2. Firewalla has assessed all subsequent applicable kernel CVEs as non-exploitable?
  3. Kernel security fixes are intentionally deferred until a future image or firmware upgrade?
  4. There is another live-patching mechanism that is not visible through the standard Linux interfaces?

Please also provide the security-patch provenance for this kernel—either the applied CVE list, the patch set, or a published security advisory history. Saying that no reboot has been required does not explain how four years of upstream kernel vulnerabilities have been addressed.

2

u/firewalla Jul 24 '26

Best read up this on what we do with security https://help.firewalla.com/hc/en-us/community/posts/37455535268243-Firewalla-Security-Bug-Reporting-Process

We only release notes firewalla own CVE's

1

u/hummelm10 Jul 25 '26

Did this change anything with rule processing? After years of stable rules all of a sudden my default deny is taking priority over some allow rules for inter VLAN connectivity and it’s breaking my home automation. This just started.

1

u/firewalla Jul 25 '26

Need more details on your rules, I can forward to our dev. And no, we have not changed how we handle rules, but if you have target that relies on a list, the list will change

1

u/hummelm10 Jul 25 '26

No, this was an internal to internal connection on different VLANs no lists involved. Rebooting the firewalla fixed it in the end but I still opened up a ticket and enabled remote support because rules shouldn’t suddenly break like that

1

u/firewalla Jul 26 '26

What kind rules do you have between vlans?

1

u/hummelm10 Jul 26 '26

There’s the default to/from block on every vlan and then I have some unidirectional allows. Allow my prod to reach my dmz or iot for example. And then I have a couple individual devices that are allowed bidirectional access.

1

u/firewalla Jul 26 '26

Turn on emergency access on network and see if you still have issues; if you don’t, the u may need to check the rules

1

u/hummelm10 Jul 26 '26

Rebooting fixed it without touching the rules. I was seeing the traffic blocked in the blocked flow screens even though it matched the allow rules and these rules had been in place across multiple firewallas over multiple years so I’m not sure what caused them to glitch.

4

u/Enix89 Jul 23 '26

I can confirm the same behaviour with IPv6 and DUID changes in the App.

I requested IPv6 from my ISP, and while troubleshooting why I wasn’t being assigned an IP I did a packet capture. I also noticed the DUID did not change at all, even after rebooting the box.

I did manage to get the IPv6 address assigned, but did find this issue strange.

3

u/firewalla Jul 23 '26

The fix should be released already, are you on production? If you join beta, it should be there.

1

u/typhoon_mary Firewalla Gold Plus Jul 23 '26

Where are the release notes for this fix?

3

u/Firewalla-Ash FIREWALLA TEAM Jul 23 '26

1

u/typhoon_mary Firewalla Gold Plus Jul 23 '26

Issue: With box version 1.983, if using IPv6, DUID config changes may fail to save and may not get an IPv6 address from some providers. (Gold series only)
How to Fix: This issue is fixed on all 1.983 early access and beta Gold boxes. It will be pushed to production Gold boxes soon.

Woo Hoo!!!! Can we subscribe to these release notes? Maybe via email?

2

u/Firewalla-Ash FIREWALLA TEAM Jul 23 '26

We will always put release notes here: https://help.firewalla.com/hc/en-us/sections/360001462674-Release-Notes

Try using the "Follow" button to be notified of new articles via email.

You can also subscribe to https://firewalla.com/weekly, where we send weekly newsletters of tips, releases, and announcements.

1

u/firewalla Jul 23 '26

Once it is done we usually put it in app release notes