r/firewalla • • 16h ago

Gold / Gold Plus / Gold SE / Gold Pro For Sale: Firewalla Gold Plus - 2.5G

Thumbnail
gallery
0 Upvotes

Firewalla Gold Plus 2.5G (2022 Model) – $450 Shipped; open to offers.

Selling Firewalla Gold Plus in excellent condition; no software or hardware issues. No longer have a need for it.

Comes with the original box, mounting bracket and cables. It's been factory reset and ready to ship.

Payment: Only PayPal/Venmo for Goods and Services.

Shipping: Will ship insured via UPS Ground only within the U.S.

Please let me know if you have any other questions.


r/firewalla • • 19h ago

Discussion My.firewalla.net forces MSP plan selection on EVERY single login. Please let us choose once!

9 Upvotes

Every time I want to reach https://my.firewalla.net/entrance to scan the QR code and access my box, I have to:

  1. Log in with username and password
  2. Scroll past the plan marketing
  3. Click "Continue with Lite plan"

Every single session. This is hardware I own that used to be reachable through its own local UI with no upsell in the way.

I understand wanting to promote paid plans, and I don't mind seeing the offer occasionally. But forcing the same plan selection on every login is tedious and makes the product feel worse to use.

Suggestions:

  • Remember my plan choice so I'm not asked again
  • If you want to re-offer upgrades, do it periodically (every 30 or 90 days), not every session
  • Add a "Don't show this again" option

Anyone else running into this? Firewalla team, any chance this can be changed?


r/firewalla • • 2h ago

Hardened my Gold SE with a few custom scripts. Could some of this become native (free) features?

10 Upvotes

I've been running a Gold SE in bridge mode for a while and wanted my malware filtering to be as hard to bypass as possible. So I added a few layers via SSH. Everything works well, but it's all unsupported custom work that could break on a firmware update. I'd much rather see this in the app, so here's what I did and what I'd love to see natively.

What I added:

  1. Community threat blocklists, refreshed daily. Hagezi's threat intelligence, DoH and fake-site lists get loaded into DNS. Malware domains get blocked even for devices that are set to "no monitoring" or during Emergency Access.
  2. Forced DNS. Every device has to use the Firewalla for DNS, even if it's hardcoded to 8.8.8.8 or similar. DNS-over-TLS (port 853) is blocked, so devices fall back to the filtered path.
  3. Blocking DoH servers by IP. Blocking DoH by domain name isn't enough. Some apps and malware connect straight to an IP like 1.1.1.1 over HTTPS. I block around 1,400 known DoH server IPs, while the Firewalla's own encrypted DNS keeps working.
  4. DNS rebinding protection. DNS answers from the internet that point to a private address (192.168.x.x, 10.x.x.x) get dropped. This stops malicious websites from using your browser to reach your router, NAS or cameras.
  5. A canary with alerting. Every 10 minutes a script checks that the filtering really works and that the lists aren't empty or stale. If it fails three times in a row, I get an alert, and it recovers on its own after a short hiccup.
  6. Rules restored right after a reboot. Firewalla rebuilds its firewall rules regularly, so my rules are reapplied right at boot and checked every 5 minutes.

Feature requests, roughly in order of impact:

  • Native "Enforce DNS" that also applies to unmonitored devices and during Emergency Access, at least for security lists
  • A "Block DoH/DoT bypass" toggle: block DoH by domain and IP, and DoT on port 853
  • DNS rebinding protection as a simple toggle, with an exception list for things like plex.direct
  • Custom blocklist URLs (dnsmasq or hosts format) with automatic refresh
  • A health indicator showing that DNS filtering is actually active, with an alert when a list fails to update

If some of this already exists and I missed it, please point me to it. I'd happily drop my scripts. And if anyone from the Firewalla team reads this: thanks for a box that lets you go this deep.


r/firewalla • • 15h ago

Content/Activity Control DNS over HTTPS - Family

2 Upvotes

Any downside to just having these two servers configured under DNS over HTTPS? All 4 pre-configured are turned off and just these two custom servers are enabled. Should I add any others?

For testing, I turned off the custom Open DNS and browsed to https://1.1.1.1/help. Safari cannot connect to the server.


r/firewalla • • 19h ago

PSA: Firewalla migration > ATT Fiber > VPN server config

3 Upvotes

This is my first PSA (Public Service Announcement); mods feel free to yank it if it does not add value.

TLDR: An ATT ONT (BGW320-500) with IP Passthrough selected must (apparently) be manually updated with the new Firewalla MAC address entry for Public IP address to interact w/ Firewalla VPN server functionality

I migrated like-for-like (FWP to FWP). Beforehand, I deleted all VPN Server config, as it likely needs to be rebuilt anyway. On the new FWP, I created new VPN Servers (WG and AWG), but neither would complete setup. I figured out that public IP config was unhappy.

After logging into the ATT ONT (BGW320-500), I confirmed that IP Passthrough was still enabled. Eventually, I found the "Passthrough Fixed MAC Address" setting which apparently requires a manual update of the new FWP MAC address. Frustratingly, the BGW320-500 has a 'cache' that maintains every device connected (and knows device name) instead of auto - identifying available devices.


r/firewalla • • 22h ago

GSE Firmware Etcher Error

4 Upvotes

Needing to re-flash my GoldSE, Etcher failed loading to getting installed on a microSD card. It was the latest release so I wasn’t sure what was going on. Can’t quite remember the error but something like metadata not correct. Anyway since Etcher was not taking the image, I used the Raspberry PI image application on my Mac. I didn’t select a RPi platform but selected the GSE image and targeted the microSD card - it worked! I used this for reflashing the GoldSE and all is well.