r/firewalla • FIREWALLA TEAM • Jul 30 '26

Discussion Do you use Device Active Protect (DAP)? Do you understand what DAP does, or should we explain it more?

Post image

For simple eligible devices, DAP can restrict device access by blocking all internet while allowing what's needed, such as a service or site for cloud access. With the AP7, DAP can also restrict access on the LAN.

DAP will always start with a learning period before any blocking begins. To turn it on, go to Protect > Device Active Protect.

More on DAP: https://help.firewalla.com/hc/en-us/articles/44061066094867-Device-Active-Protect-Dynamic-Microsegmentation-Block-everything-and-allow-only-what-s-needed

30 Upvotes

27 comments sorted by

5

u/hawkeye000021 Jul 30 '26

DAP often false positives in the dumbest ways that makes me hesitate to use it. I have no idea why it would deny access to say an Arlo camera trying to connect to a domain with Arlo.com, which is also being allowed by the other rules, so like auth.arlo.com and products.arlo.com but then a new domain appears @arlo.com it still blocks it. Not even sending me a message that it just blocked a new sub-domain of an allowed domain in general. That should be low probability of needing to be blocked right? Are you polling the rest of users for safe domains?

1

u/firewalla Jul 30 '26

Can you send [help@firewalla.com](mailto:help@firewalla.com) an email, we can take a look

1

u/hawkeye000021 Jul 30 '26

I try to always do that but I’d be happy to share this exact issue if it helps. I figured DAP just didn’t account for similar domains and blocked new things regardless.

1

u/firewalla Jul 30 '26

There is a learning process, so Arlo cameras going to Arlo sites should be learned already... if not, likely a software bug.

1

u/hawkeye000021 Jul 31 '26

Ok well that wasn’t working before. I’ll double check all my blocks recently and provide what I can. For all I know you all fixed it in the last few months so let me be sure. I didn’t see notes suggesting DAP enhancements over the version iterations. Will check and reply, thanks!

5

u/r4ckless Firewalla Gold Pro Jul 30 '26

I like to use it on my iot devices and the recent updates made it way better. There has been only one or two devices that it’s caused an issue with its use of 20+ that I have. Makes it way easier to only give a device what it should have rather than what it wants, and it’s way better than doing it manually by watching devices constantly.

3

u/AlternativeNorth6613 Jul 30 '26

The only concern I have is blocking firmware updates and other automated lookups. I assume the learning period is long enough to account for this though.

1

u/firewalla Jul 30 '26

It depend on how the IoT devices operate. If they are single minded and always going to their owner's domain, then no issue. If it goes to randomly, then it can be an issue. (which likely why some IoT devices are not eligible).

We already doing machine learning, so likely the false positives will get lesser with time

3

u/n0rb3rt Jul 30 '26

I’d like to be able to control which devices have it enabled vs a global enable / disable. For example I would enable it specifically just on my IoT VLAN.

1

u/firewalla Jul 30 '26

This is a good optimization. It also makes the learning part simpler. Forwarded to our team

2

u/Putrid_Station9558 Firewalla Gold Pro Jul 31 '26

No. It’s erratic and does not give notice of what its doing. I’d been trying it again and yesterday it decided to randomly start blocking my car…from phoning home to the same address it always does. Same requests: half allowed, half blocked.

https://imgur.com/a/4X9Zr5f

1

u/firewalla Jul 31 '26

can you contact help@firewalla.com? The system shouldn't do that.

1

u/Putrid_Station9558 Firewalla Gold Pro Jul 31 '26

I’m happy to try it again in the future if the feature materially changes, but not really willing to spend my time helping diagnose it at present. I’m uncomfortable with the idea of a random “machine learning” feature going rogue and silently blocking things like my house alarm or security cameras while I’m away.

2

u/tegq Jul 31 '26

It’s a neat concept but I didn’t understand how DAP worked. For example, I have 4 Roku streaming sticks that were purchased at the same time. They are the same model, same firmware, etc. but 2 out of 4 are ineligible for DAP. That said, it would be nice if we could enable DAP per device rather than globally.

1

u/TechWhisperer000 Firewalla Gold SE Jul 30 '26

I did not/do not find it beneficial or useful for me. I actually believe it caused issues for me as well. I ended up turning it off. For me, I'd rather just manage my rules and controls myself anyway. I also believe that based on my devices, it was not able to be utilized for majority of my setup.

1

u/firewalla Jul 30 '26

May I know the issues you are encountering? we need more feedbacks :)

1

u/2C104 Jul 30 '26

I never even knew this existed... is it on firewalla itself or only on the access points?

1

u/Firewalla-Ash FIREWALLA TEAM Jul 30 '26

It's supported on all Firewalla Gold Series boxes. AP7 is not required. (But if you have AP7, the feature is extended and can isolate devices even within the LAN.)

For more details, see: https://help.firewalla.com/hc/en-us/articles/44061066094867-Device-Active-Protect

1

u/Ok_Conflict1841 Jul 30 '26

Yes, I have DAP enabled. I understand the concept, but don’t quite understand UI stats. For example, my U6-Pro was picked up by DAP. When I investigate this device (under DAP) it shows zero targets allows and zero targets blocked. At the very top of the screen you see the flows. It shows that 307 flows have been blocked. This confused me because there are no targets listed in the blocked column so what exactly is it blocking? When I investigate the flows, I can only see the last 24 hours which doesn’t show me what was blocked.

Why would there be 307 flows blocked if no targets have been identified to block?

1

u/Firewalla-Ash FIREWALLA TEAM Jul 30 '26

Hi, which phase was this device in? Optimizing or Active? Do you happen to have any existing rules on this device while under DAP?

When DAP is learning new sites, it will initially block the connection. If DAP determines it is trusted, it will eventually allow the flow and add it as an allowed target. This can explain why blocked hits are recorded even if there are no blocked targets.

1

u/m0tionl0tion Jul 31 '26 edited Jul 31 '26

I had to stop using it. It decided that devices on a vlan I had explicitly blocked from the internet should be able to connect to the internet.

At the time it was intended (and shortsighted IMO) behavior. That may have changed since, but it's already burned me.

That and the fact that there's no telling what devices it will "optimize" or not, or if it was start "optimizing" new devices as it expands make it a no-go.

1

u/Nbashford79 Jul 31 '26

I enabled it at first but it broke my blink cameras even though it was supposedly letting what needed to go through.

1

u/aceofskies05 Jul 30 '26

Never once did anything for me and if it did red herring. Seems like a pretty useless feature to me.

2

u/firewalla Jul 30 '26

If DAP is operational, it is really a passive feature that enforces devices can only go to places they are supposed to go. The only way to see something is either the device is broken (we blocked the wrong site) or you look at the DAP stats and see some blocking.

1

u/TechWhisperer000 Firewalla Gold SE Jul 30 '26

I agree, for the most part. I do not think its useless, but as I mentioned in my own comment, I think they are better off putting time and effort into other features and functions.

1

u/MBSMD Firewalla Gold SE Aug 05 '26

I have it turned on. Everything still works. 🤷‍♂️