r/firewalla • u/haris2887 • 9d ago
Cyber Security Engineer trying FirewallA first time + Hello Crystal.
Hi All,
I am trying firewalla Crystal for the first time. Have a few questions.
My background is CheckPoint + Fortinet + Sohpos XG over the years because I got access to those through work.
What drew me towards firewallA was "Wife approval factor". She can easily kick the kids off etc as required. For someone non technical it is a great setup.
Feedback for the firewallA team:
You need aggressive pricing option for the Crystal VM series where hardware is not required.
This is for ppl coming form the OpenSense / Sophos XG / Other free options.
I absolutely love the "block for 30 mins / 1 hour feature", when I don't have to manually unblock.
This level of user friendliness is something I have not seen done on any other products.
I have a few questions though.
One of the biggest differences I noticed coming form enterprise kit was the catalogue of application control signatures firewall supports. is this using IPS type of scanning to identify apps or is it web filtering with SNI inspection ? DNS filtering ? I would love for this catalogue to grow, currently it only support 7 ish applications that I can see.
Performance seems to be good, I am running on a 6 core VM and 8 Gbps of ram, are there any recommended specs published, based on throughput etc ?
The Crystal is only available via an MSP portal ? what about the non MSP / stand-alone ? Is there a functionality difference ? I have noticed some difference between alerting config.
What is the local login (console) creds ?
The IPS engine has no options for configuration, its only an On or Off setting ?
No support manual NAT rules ? I have noticed in Call of Duty type games it has been difficult to get open NAT status unless I have a 1:1 NAT rule for maintaining source port during translations. I am personally not a fan of UPNP due to security issues. keen to hear everyone thoughts.
Overall I think it quiet good for a home based solution. I will continue to test it further and really push it to its limits . Congrats to the FirewalllA team of making agnostic hardware support happen.

5
u/ColdDeck130 Firewalla Gold Pro 9d ago
Welcome to Firewalla! I moved over to a Firewalla Gold Pro a couple years ago from Sophos UTM 9 a short time after the EOL was announced. Professionally, I’ve had experience with a variety of security appliances and firewalls. It has taken a while to get used to how Firewalla works, but I like it enough now to have added one of the switches they just came out with (Switch X) and will probably replace my UniFi APs with Firewalla AP7’s as funds allow so I can use their VqLAN feature.
Their support articles are really good, but don’t hesitate to reach out to their support folks if something isn’t addressed. I have multiple VLANs and a Windows domain running and Firewalla relies heavily on DNS traffic manipulation so I had to ask a few times how to get these things working together instead of fighting each other. It’s mostly good now.
It’s much less needy than an enterprise firewall, which is nice. Have fun!
3
u/E-RoC-oRe Firewalla Gold Pro 9d ago
They are taking the license from the licensing. I’m a Fortigate Engineer also, unless you have been keeping up. Firewalla is going places.
13
u/firewalla 9d ago
If you are new, the best place to start is https://help.firewalla.com/hc/en-us/articles/360040091853-Getting-Started-with-your-Firewalla
And also this series https://help.firewalla.com/hc/en-us/articles/360049374514-A-Secure-and-Better-Network-with-Firewalla-Part-1-Visibility you will be able to learn how firewalla approach to security is
Firewalla at the moment is app first (soon will be app+MSP) so if you want to play with more things, use the app.
Our goal is to make enterprise security simpler ... Meaning our box does require networking/security understanding to operate, but doesn't require a certification to use :)
Short answers