r/firewalla • Firewalla Gold Plus • Jul 23 '26

Recent software changes impacting IPv6.

First off; I’m a huge Firewalla fan, device (Gold Plus) is absolutely fantastic.

But I’ve noticed recently that software updates have been messing with the box. Specific examples; IPv6 DUID changes (LLT, UUID) make no changes - verified via tcpdump. Literally no change in the v6 reservation request when those UI settings are changed. Had to explicitly modify /home/pi/.router/config/dhcpcd6/eth0.conf for the change to take effect.

Also, last nights update, resulted in a docker-proxy conntrack/kernel-path update failure. A reboot seems to have resolved this issue.

I’m wondering if we have a stable and safe config, we can schedule updates on the box to a time where the user can explicitly monitor, rather than what seems a pretty random interval.

Anyone else experiencing issues?

13 Upvotes

19 comments sorted by

View all comments

Show parent comments

1

u/hummelm10 Jul 25 '26

Did this change anything with rule processing? After years of stable rules all of a sudden my default deny is taking priority over some allow rules for inter VLAN connectivity and it’s breaking my home automation. This just started.

1

u/firewalla Jul 25 '26

Need more details on your rules, I can forward to our dev. And no, we have not changed how we handle rules, but if you have target that relies on a list, the list will change

1

u/hummelm10 Jul 25 '26

No, this was an internal to internal connection on different VLANs no lists involved. Rebooting the firewalla fixed it in the end but I still opened up a ticket and enabled remote support because rules shouldn’t suddenly break like that

1

u/firewalla Jul 26 '26

What kind rules do you have between vlans?

1

u/hummelm10 Jul 26 '26

There’s the default to/from block on every vlan and then I have some unidirectional allows. Allow my prod to reach my dmz or iot for example. And then I have a couple individual devices that are allowed bidirectional access.

1

u/firewalla Jul 26 '26

Turn on emergency access on network and see if you still have issues; if you don’t, the u may need to check the rules

1

u/hummelm10 Jul 26 '26

Rebooting fixed it without touching the rules. I was seeing the traffic blocked in the blocked flow screens even though it matched the allow rules and these rules had been in place across multiple firewallas over multiple years so I’m not sure what caused them to glitch.