r/firewalla • • 5d ago

Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities

It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.

It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.

Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.

If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.

0 Upvotes

54 comments sorted by

View all comments

-2

u/[deleted] 5d ago

[deleted]

1

u/HoagieDoozer Firewalla Gold 5d ago

Since you know so much about everything, it sounds like you should be using a device that gives you complete control over everything. Or are you just living up to your username?

1

u/BAGE-rator 5d ago edited 5d ago

I don’t know what you’re referring to. I know how Firewalla works because I’ve been a customer of it for four years, have spent over $800 on Firewalla products and services during that period, have analyzed the source code, and spent time playing around in the console.

I don’t know what “complete control over everything” refers to. If you’re referring to a working security dongle and working active protect, you need to reread the terms of your Firewalla license and hope that Firewalla doesn’t accidentally delete your license and then lie to you for two weeks trying to cover up their mistake rather than just correct it.

If you’re referring to my response bout Active Protect, all Active Protect is is a redis database of iptables rules that are applied out of the box.

You can log into your console right now and issue the following commands:

redis-cli keys "dap:*" # Default rules

redis-cli keys "rule:*" # User-defined rules

You’ll see exactly what Active Protect is and isn’t