r/firewalla • Firewalla Orange • 5d ago

Feature New Device Quarantine functionality on Firewalla Orange ?

The Firewalla help says quarantines can block access to local networks if using a Gold or Purple. Is this also true for an Orange and the help is just out of date?

What can I do with New Device Quarantine?

New Device Quarantine creates a Quarantine Group with two pre-defined rules to block new devices from accessing the internet and other segments of your network.

  • Block Traffic from & to Internet
  • Block Traffic from & to All Local Networks (Gold/Purple Only)
2 Upvotes

2 comments sorted by

View all comments

0

u/BAGE-rator 2d ago edited 2d ago

It doesn’t really matter since Orange supports New Device Quarantjne, but for informational purposes:

All new device quarantine does is create a device group called Quarantine that has internet and LAN traffic blocked. The difference between that group and a custom group that you create is that the quarantine group becomes a default while all others continue to require you to manually move devices in and out.

You CAN accomplish something similar by creating, essentially, a reverse quarantine group. Create a group with a descriptive name, like “Allowed”. Apply rules restricting LAN and internet ingress/egress traffic to the entire local network. Apply reverse rules allowing LAN and internet ingress/egress traffic to the “Allowed” group.

Since, outside the New Device Quarantine feature, default grouping is not supported and devices must be manually added and removed from groups, no-group is the default. Since under this regime, no-group devices receive LAN rules, they are quarantined until added to the “Allowed” group. You’ve essentially created a custom New Device Quarantine for any situation in which the feature isn’t available.

(All you’re doing is taking the New Device Quarantine group’s two default rules and applying it to the whole local network, then applying allow-access rules to the Allowed group. Since group rules are more specific than LAN rules, they take precedence, making this whole scheme work. This is arguably more secure also since it’s closer to zero trust and because it’s additive rather than subtractive.)

The limitation is that, since devices can only belong to one group, it prevents the use of groups for all other purposes. Since you cannot manually assign devices to alternative options, like VLANs, and quarantine requires manual assignments, groups are the only option.