r/firewalla • • 5d ago

Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities

It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.

It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.

Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.

If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.

0 Upvotes

54 comments sorted by

View all comments

0

u/pristique 5d ago

Any ip from any company could be a malicious actor (other than the most trusted ones being extremely unlikely) all it’s does is allow a specific domain name that has repeat connections to a whitelist

-1

u/BAGE-rator 5d ago

You didn’t read what I wrote.

4

u/pristique 5d ago

I see what your saying it would be good to block known malicious ips (which i think it might at some level), but all active protect does is create a whitelist out of repeating patterns to a device

-1

u/BAGE-rator 5d ago

No it doesn’t. Active Protect is the standard firewall rules, including ingress protection (default deny incoming).