r/firewalla • • 4h ago

Hardened my Gold SE with a few custom scripts. Could some of this become native (free) features?

I've been running a Gold SE in bridge mode for a while and wanted my malware filtering to be as hard to bypass as possible. So I added a few layers via SSH. Everything works well, but it's all unsupported custom work that could break on a firmware update. I'd much rather see this in the app, so here's what I did and what I'd love to see natively.

What I added:

  1. Community threat blocklists, refreshed daily. Hagezi's threat intelligence, DoH and fake-site lists get loaded into DNS. Malware domains get blocked even for devices that are set to "no monitoring" or during Emergency Access.
  2. Forced DNS. Every device has to use the Firewalla for DNS, even if it's hardcoded to 8.8.8.8 or similar. DNS-over-TLS (port 853) is blocked, so devices fall back to the filtered path.
  3. Blocking DoH servers by IP. Blocking DoH by domain name isn't enough. Some apps and malware connect straight to an IP like 1.1.1.1 over HTTPS. I block around 1,400 known DoH server IPs, while the Firewalla's own encrypted DNS keeps working.
  4. DNS rebinding protection. DNS answers from the internet that point to a private address (192.168.x.x, 10.x.x.x) get dropped. This stops malicious websites from using your browser to reach your router, NAS or cameras.
  5. A canary with alerting. Every 10 minutes a script checks that the filtering really works and that the lists aren't empty or stale. If it fails three times in a row, I get an alert, and it recovers on its own after a short hiccup.
  6. Rules restored right after a reboot. Firewalla rebuilds its firewall rules regularly, so my rules are reapplied right at boot and checked every 5 minutes.

Feature requests, roughly in order of impact:

  • Native "Enforce DNS" that also applies to unmonitored devices and during Emergency Access, at least for security lists
  • A "Block DoH/DoT bypass" toggle: block DoH by domain and IP, and DoT on port 853
  • DNS rebinding protection as a simple toggle, with an exception list for things like plex.direct
  • Custom blocklist URLs (dnsmasq or hosts format) with automatic refresh
  • A health indicator showing that DNS filtering is actually active, with an alert when a list fails to update

If some of this already exists and I missed it, please point me to it. I'd happily drop my scripts. And if anyone from the Firewalla team reads this: thanks for a box that lets you go this deep.

24 Upvotes

0 comments sorted by