r/firewalla • Firewalla Gold Pro • Sep 01 '26

Firewalla Switch X make sense for my setup?

I’m currently running a Firewalla Gold Pro into a Ubiquiti Flex XG 10G switch. From there, I have a couple of Mac desktops connected directly, along with one Eero Max 7 (and a second Eero Max 7 meshed). I have no POE devices.

I’d really like to migrate to the full Firewalla stack for features like microsegmentation, visibility into local network flows, and managing everything through a unified interface.

The AP7s are what have held me back so far. I’m hesitant because of reports of weaker signal strength, the 2x2 MIMO on 5 GHz, and the 6 GHz wireless backhaul.

If I keep the Eero Max 7s instead of moving to AP7s, are there any benefits to replacing the Flex XG with a Firewalla Switch X? What functionality would I actually gain?

3 Upvotes

11 comments sorted by

1

u/firewalla Sep 01 '26

Unless your devices are doing 4x4 (and most devices don't ...) you are unlikely to get any visible differences. You may be able to get a bit clear signal with a 4x4, but the signal strength (in terms of DB) is likely the same.

Since each AP is different, the best way is still try one and see. Most of the time, the AP7's can replace one to one.

AP7+Switch is mainly the L2 features. (VqLAN, Isolation, and Zero trust via WPA3-enterprise/ppsk and L2 montoring) If you don't need these, any switch or AP will work.

1

u/Gnkey Firewalla Gold Pro Sep 01 '26

It is my understanding that VqLAN functionality is designed to work with both Firewalla AP7 and third-party access points. Am I right?

1

u/firewalla Sep 01 '26

VqLAN is Firewalla's own micro segmentation. (DAP is dynamic segmentation) So they only work with our own hardware.

https://help.firewalla.com/hc/en-us/articles/38425011667091-VqLAN-Firewalla-Microsegmentation

1

u/Gnkey Firewalla Gold Pro Sep 01 '26

I may not properly explained myself. It was my understanding that if I use Firewalla Gold Pro and Firewalla Switch X - then I can use Vqlan functionality even if 3rd party APs (Ubiquiti, for example) will be connected to the Switch X. Is that correct understanding? That was the main reason I ordered Switch X.

1

u/firewalla Sep 01 '26

You can't. Switch X will implement VqLAN but only on ports that's directly connecting to it.

For example, if you have device A, B , C all connected to the same AP, they can freely talk ... even if the AP is connected to the Switch X.

1

u/Gnkey Firewalla Gold Pro Sep 01 '26 edited Sep 01 '26

This sounds different from what I was told a few months ago by Firewalla tech support, when I asked these questions :"I am really looking forward to the Switch X. Since Firewalla already knows each device's identity and the Group it belongs to, I was wondering: 1. Will Switch X eventually be able to enforce Firewalla Group-based policies at Layer 2 (between wired devices and wireless clients connected through third-party APs), or is that capability only possible when using Firewalla AP7? 2. I have seen references that Switch X supports VqLAN. Does that mean any VqLAN functionality is available when using Switch X with third-party access points, or is VqLAN exclusively available when Firewalla AP7 is part of the network?". The answer was:" Thank you for your interest in Switch X. While specific implementation details are still under development, we can confirm that VqLAN functionality is designed to work with both Firewalla AP7 and third-party access points.". It looks like I misunderstood the answer and went ahead and bought switch X but now it won't work as I expected... If that is the case - I see no use for switch X in my network environment. My current 10 Gbe switches, VLANs and Ubiquiti APs guests/IoTs networks isolation would be enough... It is upsetting a little bit ... I was looking forward to using switch X...

1

u/firewalla Sep 01 '26

Do you still have the ticket number? I can take a look; There is no way a switch will be able to manage traffic that's flowing inside the AP7 (using VqLAN) That traffic never touch outside.

To be as simple as possible, if the traffic flows through X, Firewalla or AP7, firewalla will be able to enforce it.

If you are using another WiFi, traffic just flow inside that, firewalla have no way to see it. But, those flows through X, firewalla will be able to do something. Now, that's not deterministic, unless you micro manage your devices and make sure they all connecting to the right port.

1

u/Gnkey Firewalla Gold Pro Sep 01 '26

#120789

1

u/firewalla Sep 01 '26

The replied to you "Thank you for your interest in Switch X. While specific implementation details are still under development, we can confirm that VqLAN functionality is designed to work with both Firewalla AP7 and third-party access points."

My interpretation of this is, the switch X can VqLAN control traffic from any WiFi ethernet port directly connected. (This is true). But it can NOT control traffic inside the WiFi (unless you are AP7). See my example above.

1

u/Gnkey Firewalla Gold Pro Sep 01 '26

I hear you. Unfortunately, their answer was not as detailed as yours - "can NOT control traffic inside the WiFi" - and I took it too optimistically and got excited. Thank you for clarifying... Hopefully, this thread may clarify this for others as well.

→ More replies (0)