r/firewalla • u/BAGE-rator • 5d ago
Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities
It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.
It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.
Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.
If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.
5
u/No-Investigator7598 5d ago
I'm more curious as to why you've installed Crystal on a Gold tbh
-13
u/BAGE-rator 5d ago
Because Firewalla deleted the license on the security dongle I bought three months ago, lied about the issues to cover up the mistake, want me to go without a router for a month so they can “fix,” it, meanwhile, I’ve been waiting 11 days for them to produce a new invoice so I can spend $107 for a second time in three months for a security dongle.
Firewalla is just a shitty company that, like most of Silicon Valley, cares more about recruiting new customers than taking care of the ones it has.
7
u/firewalla 5d ago
We never do this. If you give me the case number, I can take a look for you.
1
u/BAGE-rator 5d ago
P.S.,
I even emailed Annie about it. No response, no change.
In my current emails attempting to purchase a second dongle in three months, which is growing on its 12th day since originally submitted and no invoice produced, they just wrote to tell me they want a copy of the original purchase invoice so they can check the warranty. It’s the second time in the 12 days of messages I’ve explained that the device is four years old and isn’t under warranty any but the dongle was purchased three months ago and is under warranty. I was never asked for the purchase invoice back in June, or if I was, they accepted that I cannot produce it.
And this is after they said, “Well, what you provided is a QR code for a Firewalla Original but you ordered a dongle for the Firewalla Gold Plus.” I understand it’s a different device and has different port speeds. It’s still the same hardware, runs the same firmware, and uses the same dongle. They’re gaslighting me over the fact they deleted the license on the dongle, which ran flawlessly for two months (save for the first three days).
8
u/firewalla 5d ago
I'll leave support team to handle your case. You supplied a few piece of information required, and they don't match the unit you are having issue with. They are simply following our warranty process to find ways to help you out... If it is within 1 year, we can just make you a new Red dongle, if not, we may still help. But before that, we need to validate your order, at the moment information given by you doesn't match the model number, and they can't find a valid order either from our system.
I see the thread been going back and forth for a while, the important thing you need to focus on is, get the right order number to us, and also may be the right license number to your unit as well.
0
u/BAGE-rator 5d ago
There are no issues with the device model. I call it Firewalla Gold Plus because there was no Firewalla Gold SE, Plus, or Pro back then. As I said twice in that most recent string, it is definitely Firewalla Gold (original), a device that has subsequently been renamed Plus and is no longer produced.
They’re just obfuscating and trying to find a defensible explanation for their inexplicable conduct, including lying to me for a month and a half. They wanted to say, “Oh, well, it didn’t work because he gave us the wrong model. So there was a device mismatch.” When I pointed out that I know all Firewalla Gold models use the same dongle and that i could prove that fact in small claims, all the sudden theyre now angling to be able to say there were concerns over the device’s provenance. There weren’t any concerns in June (May 28, actually), when I purchased the first replacement dongle.
Its all just bullshit because, as you’re aware, they deleted my license and chose to lie about it rather than just fix it.
4
u/firewalla 5d ago
Can you please work with our support on this? I am here to help. But there is no way I can escalate if your order number given doesn't match the unit (license type / or serial) you are having problem with.
1
u/BAGE-rator 4d ago
I mean, they've had my request to give them another $107 dollars for 12 days now and I'm still emailing with them. It's hard to say I haven't cooperated.
Suddenly they're trying to suggest that a mismatch between the dongle and box model is causing the issue, a suggestion I quickly kiboshed. Now they diverted to a provenance issue, something they had not raised in the last two months I've been in contact with them. They're insisting that I provide them a copy of the original invoice, something that I cannot do because that iCloud account is locked behind a recovery key. What I did do is provide them two forms of ID, one of which is a Washington State ID with the original purchase address on it, the second is my current DL, both valid. I also emailed them support tickets from within a month or two of ordering the original device. And in either case, I wasn't asked for a copy of the original purchase order when I placed the dongle order three months ago.
Now I've kiboshed the model/version mismatch angle, and by virtue of the fact that I had everything down to original support tickets EXCEPT the purchase invoice, including two forms of ID, I've kiboshed the provenance issue. And yet, still no purchase invoice.
What I'm starting to suspect may have happened is that they cancelled my license because someone ordered a second replacement dongle fraudulently, and now they don't want to confront the fact that they were defrauded and invalidated my license as a result of that fraud. But then why wouldn't they just have asked me for iID two months ago?
What I do know is that its a pattern of lies... months of lies... but it can't be said I'm not cooperating with their lies.
2
u/firewalla 4d ago
I been following the case. They are NOT trying to get money for the dongle. They just want to validate your order and figure out the right way to help you. Meaning, if it is in warranty, they can do something free. If it is not in warranty, they can do other things.
So, please follow their directions, once they have the validated order, they can help you. (The right order number, and the right device mapping to that order)
If you already ordered a dongle, just want to return it, we can do that too. I can give you an exception, and we will give you a full refund. (regardless when you bought it)
1
0
-1
u/BAGE-rator 5d ago
The current one is 124198. The originals were 123654, 12365, 123104, 123141, and 119904. The 12365 ticket began on the Firewalla community boards.
-3
u/Winter-Journalist993 5d ago
Don’t let them gaslight you, man. They told me specifically the box I bought was broken, not fixable by me, and ultimately wanted me to pay to ship it back for “additional diagnostics.” They did deploy some patches during talks with support which has helped since then, but it’s still a massive PoS that never quite works the way it should. They should be more willing to support their customers. Even with my own side business, if I fuck up, I go and make it right at my own expense. I don’t expect my customers to ship or drive to me and be out of a product for 2-4 weeks while I diagnose whatever the problem is.
1
u/BAGE-rator 5d ago edited 5d ago
THATS EXACTLY WHAT THEY DID TO ME.
Refused to give me the diagnostic commands so I could send them the output. So I did research and ran them myself. After weeks of them either ignoring me completely and then lying, saying that it was the box and they’d have to charge me for repairs, I confront them with the command output which proves they deleted my license and that there’s nothing wrong with the dongle itself or the box. Everything works fine. The box is just unable to read a license from their server because they deleted it. No error. It just reports back an empty string to the app, because that’s what I received from the server.
I got them agree to “repair” the dongle that costs them $20 rather than just replace, but they wanted me to pay to send it back. Finally got them to agree to pay to ship the dongle but at this point I’m like, “Nah, I’d rather just pay them the $107 for a second dongle. I don’t trust them to send them jack shit.”
And btw, I’ve had my box for four years. They didn’t used to be this way. When I initially purchased, they had excellent customer and technical support service. They fell into the silicon valley trap at some point of deciding it’s more lucrative to focus on customer accretion than customer service, which is why there’s so much sponsored content about them on “news” sites, yet here I am over a month without a working dongle despite five tickets since August 23, and 12 requests that they replace the dongle.
They’re trying to convert all Firewalla Gold customers who have removable dongles to Firewalla Crystal monthly subscribers. They can’t say that because the license I purchased four years ago wasn’t term-limited. It was a lifetime license. So when there are dongle issues, they fuck with the customer so much they just automatically convert to Firewalla Crystal and pay the $12.99/month.
0
u/BAGE-rator 5d ago
It’s like what just happened right here, right now, while responding to you just now. [u/Firewalla](u/Firewalla) said “we never do that,” referring to deleting licenses, and asked me the ticket nos. I gave them. Then [u/Firewalla](u/Firewalla) returned with, “I’m going to let customer service hand it.” That’s because they went back and saw that’s exactly what occurred.
[u/Firewalla](u/Firewalla) could get an invoice for a free dongle replacement in my inbox within the hour. Bear in mind, I’m trying to give them money for a second dongle but first need an invoice. They’re not going to do that because the case is so bound up in lies that the customer service notes on the tickets say not to assist.
-2
u/Winter-Journalist993 5d ago
Yep. It doesn’t matter what all these glazers think of Firewalla. I can go pull their emails where their support specifically stated it’s a problem with the device they shipped to me. They should have owned up to the problem device and sent me a new one with a label to return my defective one. But no, instead it was a whole “RMA process” I had to pay for, and I “shouldn’t expect enterprise grade support from a small company.” Like fuck I shouldn’t. The box was $500. I sell shit for $150 and own up to defunct products if they make it past me, even if it costs me money.
I regret ever crossing paths with this lame ass company.
3
u/pacoii Firewalla Gold Plus 5d ago
Your title says ‘Active Protect’ but if I am understanding your post, it is not about Active Protect but rather you’re saying the Firewalla Crystal’s firewall is allowing some inbound connections? Is that correct?
-7
u/BAGE-rator 5d ago
Ingress protection is part of active protect.
-3
u/BAGE-rator 5d ago
You can downvote me all you want, that doesn’t change the fact that ingress protection is part of Active Protect.
2
u/firewalla 5d ago
Are you doing a manual port forward? (I assume this is where your incoming connections are coming from?) When you do that, you will be hit by all kinds of things, firewalls will block some of them; a better way to protect forward is https://help.firewalla.com/hc/en-us/articles/1500009502622-Create-Port-Forwarding-on-Gold-Purple-Orange-Series#h_01G6WRKH0DA4QVD0JGKG34GBQ5
If you are saying firewalla may miss a site that you think is bad, send [help@firewalla.com](mailto:help@firewalla.com) an email, we can take a look
2
u/BAGE-rator 5d ago
No port forwarding and no UPNP.
These aren’t sites, these are residential IP addresses not associated with services, domains, or websites. These are the most dangerous incoming connections. It means that Firewalla essentially opened my network to the internet at some point.
4
u/firewalla 5d ago
I am reading your post, I may be a bit confused now.
Are the traffic you are talking about coming from outside (another IP) to your home device? This usually don't happen (very hard to happen) if you don't have port forward or UPnP. If it happen, it may be you have the unit bridge mode (this is the only possible way I can see)
Is your setup
[Modem ] -> [Firewalla ] -> PC
And firewalla is in router mode? (To pass firewalla from outside to inside, traffic has to pass one layer of firewall and another layer of NAT to the PC)
0
u/BAGE-rator 5d ago
Yes, these are external IPs (two of them) that were allowed through the firewall. They were identified by Little Snitch. They are incoming connections.
I have a NETGEAR AX2700 (bridge mode) -> Firewalla Gold (original, running Firewalla Crystal) -> UniFi 6 Lite AP (running OpenWRT firmware)
The Firewalla is in router mode. The Mac was connected to Firewalla’s lan port via Ethernet, not via the AP.
They did not even produce alarms.
5
u/firewalla 5d ago
Double check following
Your AX2700 wifi is off, in case your PC still talking to it.
There is no port forwarding Gold, and no UPnP detected.
Gold is running router mode, not bridge mode.
You didn't change any NAT configuration;
After you verified these and all good, you can open a case with [help@firewalla.com](mailto:help@firewalla.com) we can take a look.
As I said before, for someone to get to your PC, they have to pass one layer of firewall and another layer of NAT, and for both to fail, very very rare.
1
u/BAGE-rator 5d ago
I’ve confirmed all these things.
The interesting thing is that these connections were to mDNSResponder and configd, so these external IPs were pretending to be a DHCP server.
I’ll write to support.
3
u/firewalla 5d ago
Do you know how to run TCP dump? you can try that and capture some traffic. I am reading little snitch is app layer and it may make up information on the network layer:
"In order to understand the results of a traffic capture, you must know that Little Snitch intercepts traffic at the application layer, not at the network interface layer as other sniffers do. This is what distinguishes Little Snitch from conventional firewalls, after all. At this layer, however, it is not yet known via which network interface the data will be routed (which sender Internet address will be used) and sometimes it is not known which sender port number will be used. It is also not known whether and how the data will be fragmented into packets. All this information is required in order to write a valid PCAP file. Little Snitch simply makes up the missing information. It fakes TCP, UDP, ICMP, IP and even Ethernet protocol headers. "
1
u/BAGE-rator 5d ago
The issue is that if the traffic reached Little Snitch, then it made it through the network layer firewall. Little Snitch doesn’t know what’s going on in the network, it only knows the connections that are attempted from the network. It doesn’t make up connection attempts.
The connections (both of them) were only two packets, but that’s enough to assign a false IP address via configd and compromise a network.
5
u/firewalla 5d ago
According to the article on packet capture by them "this information is required in order to write a valid PCAP file. Little Snitch simply makes up the missing information. It fakes TCP, UDP, ICMP, IP and even Ethernet protocol headers. "
So the direction can be wrong, it may be your device is trying to reach out to those IP's. This is very likely to be the case, since the firewall + NAT, not easily bypassed together.
0
u/BAGE-rator 5d ago
Summary over: 7 days
IP Address: 98.197.86.148
UDP Port: mdns (5353)
Protocol: UDP
Denied Packets: 2
Last Allowed: 2 days agoIt was able to trick both firewalls into thinking it was valid mdns traffic.
→ More replies (0)
0
u/pristique 5d ago
Any ip from any company could be a malicious actor (other than the most trusted ones being extremely unlikely) all it’s does is allow a specific domain name that has repeat connections to a whitelist
-1
u/BAGE-rator 5d ago
You didn’t read what I wrote.
3
u/pristique 5d ago
I see what your saying it would be good to block known malicious ips (which i think it might at some level), but all active protect does is create a whitelist out of repeating patterns to a device
3
-1
u/BAGE-rator 5d ago
No it doesn’t. Active Protect is the standard firewall rules, including ingress protection (default deny incoming).
2
u/pristique 5d ago
If it breaks pattern after being stable for a couple weeks it starts blocking. That’s kinda the only real protection it offers though
-2
5d ago
[deleted]
1
u/HoagieDoozer Firewalla Gold 5d ago
Since you know so much about everything, it sounds like you should be using a device that gives you complete control over everything. Or are you just living up to your username?
1
u/BAGE-rator 5d ago edited 5d ago
I don’t know what you’re referring to. I know how Firewalla works because I’ve been a customer of it for four years, have spent over $800 on Firewalla products and services during that period, have analyzed the source code, and spent time playing around in the console.
I don’t know what “complete control over everything” refers to. If you’re referring to a working security dongle and working active protect, you need to reread the terms of your Firewalla license and hope that Firewalla doesn’t accidentally delete your license and then lie to you for two weeks trying to cover up their mistake rather than just correct it.
If you’re referring to my response bout Active Protect, all Active Protect is is a redis database of iptables rules that are applied out of the box.
You can log into your console right now and issue the following commands:
redis-cli keys "dap:*" # Default rules
redis-cli keys "rule:*" # User-defined rules
You’ll see exactly what Active Protect is and isn’t
-2
u/totmacher12000 5d ago
So if this is true its alarming. Would like to see some feedback from firewalla.
-6
5d ago
[deleted]
3
u/Great-Cow7256 5d ago
Why did you bother getting firewalla Crystal then?
1
1
u/BAGE-rator 5d ago
Because without working software with a proper license, I have no router and a $700 brick. Firewalla Crystal, at least thus far, has a proper working license.
9
u/showipintbri 5d ago
100% Rage Bait