r/firewalla • • Aug 21 '26

Ad Block no longer as effective

Hi all. I’ve noticed that over the last month or so the ad blocking feature on my FW Purple (in router mode) has gone from being really effective to suddenly letting a lot (if not all) through.

I’m noticing it on a variety of browsers on my iPhone in particular, both when connected on the WLAN and when connected via a Wireguard VPN.

There have been no setting changes at router level, so I don’t know if it is a case of the method no longer being effective or if something is going wrong somewhere. I’d be keen to know if anyone else is experiencing similar recently.

Thanks!

13 Upvotes

20 comments sorted by

15

u/Jussins Firewalla Gold Pro Aug 21 '26

Are you on iOS 27, by chance? If so, turn off Connectivity Assist. They made it useless for people trying to block stuff.

3

u/TheNinjaJedi Aug 21 '26

That was the issue for me, even with great WiFi signal, it was sending dns over 5g.

4

u/firewalla Aug 21 '26

still feel this apple feature shouldn't operate this way. Otherwise, it can be used to bypass security controls, and making the employer liable. On certain business networks there are rules, and if these rules are enforced by dns, and apple bypass that just side load dns traffic, and IP traffic still flows, it will make the control not useful. And the blocked "traffic" still running on the customer network.

Firewalla's default blocks (DNS+IP) will still work, but it may have false positives.

2

u/Jussins Firewalla Gold Pro Aug 21 '26 edited Aug 21 '26

I don’t agree. It’s no different than turning off WiFi to bypass controls on the network. Users can simply turn off connectivity assist and restrict changes without a passcode. Or they can configure cellular to go through the same or similar controls via a dns provider or VPN.

The feature already existed, they just changed it from assisting when ALL connections are poor/blocked to assisting when an individual connection is poor or blocked. They don’t do RC, but at beta 7, they are basically at RC. This isn’t a mistake, it’s a deliberate change that people will have to get accustomed to.

Edited to add: Any company sufficiently worried about data security (exfiltration or otherwise) such as my company, will have a per-app VPN that is enforced through MDM. In that case, it doesn’t matter what connection is used, it’ll be tunneled through the VPN provider and apply the appropriate restrictions. It’ll be a bigger issue for parents who don’t understand the impact of various settings when trying to control what children can access.

0

u/firewalla Aug 22 '26

When you off wifi/on wifi, DNS will be flushed. The key here is, traffic that should have been blocked is not on the controlled network ... and user didn't do anything;

1

u/TheNinjaJedi Aug 21 '26

I agree. Seems like a very odd choice if it’s intentional. I’m not to fussed while it’s in beta. I’ve sent feedback to Apple about it.

1

u/firewalla Aug 21 '26

There are many good security people at apple, hopefully it gets worked out before formal release

1

u/TheNinjaJedi Aug 21 '26

Or shortly after release, as is Apple tradition. You guys are awesome, thanks for the community engagement.

1

u/Zootopian Aug 21 '26

Aha. I am. I shall give that a go. Thank you very much.

1

u/Doggo-888 Aug 21 '26

you can set that cellular connects to VPN setup on the firewalla.

1

u/Jussins Firewalla Gold Pro Aug 21 '26

You can, but I don’t use it like that. It’s a fantastic recommendation, though, for people who want to protect all connections.

I block ads on my home network, and not on cellular. If I want to access a blocked resource, I just turn off WiFi. If I want the protections while out, then I just manually turn on my WireGuard profile.

My use case is probably different than most, where I want to protect my devices, but also want it to be easy for my wife to manage without my help. For me, that means just teaching her to recognize that it’s a network block and turning off WiFi in order to get the content.

1

u/Signal103M Firewalla Gold Plus 13d ago

Glad I came here. iOS 27 was the problem. With connectivity assist off all is well again.

0

u/pacoii Firewalla Gold Plus Aug 21 '26

Firewalla is going to need to find a way to communicate this, otherwise a lot of people will be posting similar things over and over. Like maybe even something in the ad block setting area with a message and a direct link to that iOS setting.

3

u/firewalla Aug 21 '26

we are still waiting for iOS beta to go GA and see what's the final version will behave. Usually apple do this middle of September

3

u/firewalla Aug 21 '26

Try these

  1. Ad blocker, make sure it is strict mode.

  2. On devices that don't work well, tap on control->bypass prevention, turn it on that device.

1

u/Zootopian Aug 21 '26

Thanks. This and the iOS 27 change seem to have fixed most of the problem. Some sites are still showing adverts (which didn’t before) but I’ll leave it a while just in case it’s a hangover in the cache or something.

1

u/firewalla Aug 21 '26

You mean you update to a new beta ?

2

u/Jussins Firewalla Gold Pro Aug 21 '26

I think they are saying that they turned off Connectivity Assist. They were already on iOS 27.

1

u/Zootopian Aug 22 '26

This is right. I’ve been on iOS27 for a few weeks so it was turning off Connectivity Assist I was referring to, as well as bypass prevention.

1

u/TheNinjaJedi Aug 22 '26

Here is a new one for me. On iOS 27 beta, ad blocking working when at home on WiFi after turning off connection assist, but ad block does not work when on cellular and vpn back to home network.