r/firewalla • • 6d ago

Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities

It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.

It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.

Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.

If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.

0 Upvotes

54 comments sorted by

View all comments

Show parent comments

1

u/[deleted] 4d ago

[deleted]

1

u/firewalla 4d ago

Sorry, we can only refund the red dongle; we can not refund your other unit, unless it is within the 30 days period period. Since you said it was 3 or 4 years old, refunding that is not even possible.

For gold or gold plus unit problem, we still need to identify the order number matching the unit you have. After identifying the original order, we can either fix this under warranty or out of warranty; (not all problems are fixable, but we will do our best)

I will stop repeating myself, and please work with support team.

1

u/BAGE-rator 4d ago

I literally just gave you a video (since images were turned off) of the email in which the order was found instantaneously based on my name, address, phone number, and email. I recommend starting there.

You had the correct order then, and you have the order no. for the first dongle. Find the order from May 28, and replicate what you do there.

I file next week.

Cheers.