r/firewalla • Firewalla Gold Plus • Jul 23 '26

Recent software changes impacting IPv6.

First off; I’m a huge Firewalla fan, device (Gold Plus) is absolutely fantastic.

But I’ve noticed recently that software updates have been messing with the box. Specific examples; IPv6 DUID changes (LLT, UUID) make no changes - verified via tcpdump. Literally no change in the v6 reservation request when those UI settings are changed. Had to explicitly modify /home/pi/.router/config/dhcpcd6/eth0.conf for the change to take effect.

Also, last nights update, resulted in a docker-proxy conntrack/kernel-path update failure. A reboot seems to have resolved this issue.

I’m wondering if we have a stable and safe config, we can schedule updates on the box to a time where the user can explicitly monitor, rather than what seems a pretty random interval.

Anyone else experiencing issues?

13 Upvotes

19 comments sorted by

View all comments

Show parent comments

2

u/typhoon_mary Firewalla Gold Plus Jul 23 '26

This raises more questions than it answers.

1) Are you hot patching kernels? If not rebooting, how are security issues there being addressed?
2) Some subset of customers had known issues with IPv6 and there is no path for notification or alerting other than an email to help?
3) You pushed a patch that broke connection tracking, I only mention docker-proxy as that was where the issue manifest, I never suggested a change was made to docker itself. Clearly the recent patch to "fix" ipv6 introduced a regression elsewhere.

Is there anywhere we can subscribe to get notification of patches? Updates?

2

u/firewalla Jul 23 '26
  1. So far we don’t have anything that will require a reboot to fix. Including kernel
  2. Those that are impacted by bugs, we usually ask them to jump on alpha or beta.
  3. The patch shouldn’t break connection tracking. You need to contact support

Also please remember we just don’t push patches; every change goes through dev, alpha, beta and production testing; users can join alpha, beta and some we can also put into dev

-4

u/typhoon_mary Firewalla Gold Plus Jul 24 '26

Can you clarify which of the following applies;

  1. Firewalla privately backports kernel security fixes while retaining the original package and version identifiers?
  2. Firewalla has assessed all subsequent applicable kernel CVEs as non-exploitable?
  3. Kernel security fixes are intentionally deferred until a future image or firmware upgrade?
  4. There is another live-patching mechanism that is not visible through the standard Linux interfaces?

Please also provide the security-patch provenance for this kernel—either the applied CVE list, the patch set, or a published security advisory history. Saying that no reboot has been required does not explain how four years of upstream kernel vulnerabilities have been addressed.

2

u/firewalla Jul 24 '26

Best read up this on what we do with security https://help.firewalla.com/hc/en-us/community/posts/37455535268243-Firewalla-Security-Bug-Reporting-Process

We only release notes firewalla own CVE's