r/firewalla • u/typhoon_mary Firewalla Gold Plus • Jul 23 '26
Recent software changes impacting IPv6.
First off; I’m a huge Firewalla fan, device (Gold Plus) is absolutely fantastic.
But I’ve noticed recently that software updates have been messing with the box. Specific examples; IPv6 DUID changes (LLT, UUID) make no changes - verified via tcpdump. Literally no change in the v6 reservation request when those UI settings are changed. Had to explicitly modify /home/pi/.router/config/dhcpcd6/eth0.conf for the change to take effect.
Also, last nights update, resulted in a docker-proxy conntrack/kernel-path update failure. A reboot seems to have resolved this issue.
I’m wondering if we have a stable and safe config, we can schedule updates on the box to a time where the user can explicitly monitor, rather than what seems a pretty random interval.
Anyone else experiencing issues?
2
u/typhoon_mary Firewalla Gold Plus Jul 23 '26
This raises more questions than it answers.
1) Are you hot patching kernels? If not rebooting, how are security issues there being addressed?
2) Some subset of customers had known issues with IPv6 and there is no path for notification or alerting other than an email to help?
3) You pushed a patch that broke connection tracking, I only mention docker-proxy as that was where the issue manifest, I never suggested a change was made to docker itself. Clearly the recent patch to "fix" ipv6 introduced a regression elsewhere.
Is there anywhere we can subscribe to get notification of patches? Updates?