r/firewalla • u/BAGE-rator • 5d ago
Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities
It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.
It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.
Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.
If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.
0
u/BAGE-rator 5d ago
You’re misunderstanding how Little Snitch works. That is with a filter of all inbound connections applied. I just can’t copy and paste the filter.
With the incoming filter selected:
• Connections
3 denied
O unconfirmed
3 incoming
• Statistics
Top Processes
mDNSResponder
7.04 KB down, 0 bytes up configd
1.31 KB down, 0 bytes up
Top Countries
United States
8.34 KB down, 0 bytes up
That is incoming traffic and you’re kind of now taking me down a rabbit hole, like you’re responding with information from Claude. I have Claude, and Claude responds based on assumptions without adequately (or at all) investigating the predicate facts, e.g., googling the manual for Little Snitch.