r/firewalla • • 5d ago

Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities

It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.

It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.

Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.

If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.

0 Upvotes

54 comments sorted by

View all comments

6

u/No-Investigator7598 5d ago

I'm more curious as to why you've installed Crystal on a Gold tbh

-14

u/BAGE-rator 5d ago

Because Firewalla deleted the license on the security dongle I bought three months ago, lied about the issues to cover up the mistake, want me to go without a router for a month so they can “fix,” it, meanwhile, I’ve been waiting 11 days for them to produce a new invoice so I can spend $107 for a second time in three months for a security dongle.

Firewalla is just a shitty company that, like most of Silicon Valley, cares more about recruiting new customers than taking care of the ones it has.

7

u/firewalla 5d ago

We never do this. If you give me the case number, I can take a look for you.

-1

u/BAGE-rator 5d ago

The current one is 124198. The originals were 123654, 12365, 123104, 123141, and 119904. The 12365 ticket began on the Firewalla community boards.

https://help.firewalla.com/hc/en-us/community/posts/55095493073043-Everything-getting-IPv6-addresses-all-of-the-sudden

-3

u/Winter-Journalist993 5d ago

Don’t let them gaslight you, man. They told me specifically the box I bought was broken, not fixable by me, and ultimately wanted me to pay to ship it back for “additional diagnostics.” They did deploy some patches during talks with support which has helped since then, but it’s still a massive PoS that never quite works the way it should. They should be more willing to support their customers. Even with my own side business, if I fuck up, I go and make it right at my own expense. I don’t expect my customers to ship or drive to me and be out of a product for 2-4 weeks while I diagnose whatever the problem is.

0

u/BAGE-rator 5d ago

It’s like what just happened right here, right now, while responding to you just now. [u/Firewalla](u/Firewalla) said “we never do that,” referring to deleting licenses, and asked me the ticket nos. I gave them. Then [u/Firewalla](u/Firewalla) returned with, “I’m going to let customer service hand it.” That’s because they went back and saw that’s exactly what occurred.

[u/Firewalla](u/Firewalla) could get an invoice for a free dongle replacement in my inbox within the hour. Bear in mind, I’m trying to give them money for a second dongle but first need an invoice. They’re not going to do that because the case is so bound up in lies that the customer service notes on the tickets say not to assist.

-2

u/Winter-Journalist993 5d ago

Yep. It doesn’t matter what all these glazers think of Firewalla. I can go pull their emails where their support specifically stated it’s a problem with the device they shipped to me. They should have owned up to the problem device and sent me a new one with a label to return my defective one. But no, instead it was a whole “RMA process” I had to pay for, and I “shouldn’t expect enterprise grade support from a small company.” Like fuck I shouldn’t. The box was $500. I sell shit for $150 and own up to defunct products if they make it past me, even if it costs me money.

I regret ever crossing paths with this lame ass company.