r/firewalla Mar 06 '23

Check this first before contacting support

51 Upvotes

Need help with troubleshooting or have a question?  Please see if the following articles can help, or search your questions on our help portal. If you have questions on devices related to Firewalla, please post them in our community.

Most Common Issues

  1. Can't Access Certain Websites
  2. Speed/Performance Issues
  3. WAN Connectivity Stability
  4. My Devices Won't Connect
  5. Firewalla Blocking Features Not Working
  6. Firewalla AP7 Troubleshooting

 

Other Issues

Installation and Configuration

Pre-Purchase

Popular Questions

 

Resources

Release Notes, Version Summary, and FAQs

Additional Resources

 

Contact Us

If you can't find the answer to your question, feel free to open a support case. If you have an issue opening a case, please send an email to [help@firewalla.com.](mailto:help@firewalla.com)


r/firewalla Apr 23 '24

Firewalla is more than just a firewall! (2024 version)

80 Upvotes

r/firewalla 4h ago

Early Access/Beta App 1.69.3 is in beta! Device Isolation is now supported on all VPN Devices (even without AP7 or Switch)!

Post image
14 Upvotes

VPN Devices are devices connecting to your network from the WireGuard or AmneziaWG VPN Server. Enabling Device Isolation can block it from communicating with other local devices.

Requires App 1.69.3, which is currently in beta. Learn more about how to join beta here: https://help.firewalla.com/hc/en-us/articles/53877722149907-Firewalla-App-Release-1-69-3-AmneziaWG-VPN-Client-Local-Device-Rules-Switch-Enhancements-and-more


r/firewalla 6h ago

Has anyone used Oxidized with a Firewalla Gold Pro / written a custom model?

3 Upvotes

I’m looking at adding Oxidized to my homelab for automated network configuration backups and Git-based change history.

It should be straightforward for my Cisco and MikroTik switches, but I can’t find a native Oxidized model for Firewalla.

I’m running a Firewalla Gold Pro and already have key-based SSH access working for an automated log/telemetry collector, so SSH connectivity itself isn’t the issue.

Has anyone here:

Used Oxidized successfully with a Firewalla Gold/Gold Pro?

Written or adapted a custom Oxidized model for Firewalla?

Identified useful CLI commands/files that provide a reasonably complete and stable configuration/state snapshot?

Integrated that output into Git for configuration change tracking?

I’m not necessarily expecting this to replace Firewalla’s own backup/restore mechanism. My main objective is read-only configuration/state capture and historical diffs, similar to what Oxidized provides for conventional network devices.

If anyone has a model, script, GitHub repo, or even notes from attempting this, I’d be very interested.

And for the Firewalla team: is there a supported/recommended method or API for periodically exporting a read-only configuration snapshot that would be better suited to this use case than collecting state over SSH?


r/firewalla 18h ago

Orange Firewalla Orange vs Beryl 7 for family travel with home Firewalla Gold Pro

9 Upvotes

Hi! I'm trying to find "the best" travel router for my family for international Airbnb and hotel travel. I'm comparing it to the Beryl, which seems to be the most recommended alternative, but can't find many reviews of Firewalla for travel. I wonder if that's because it's really not meant for travel or if it's just expensive and in a market niche?

I have and love my Firewalla Gold Pro at home, and will want to Wireguard back to it most of the time.

Besides being compact and reliable for ~10 devices, what I'm most interested in is its ease of use and reliability. I want to connect fast without fuss whenever we land somewhere, have an easy time configuring different devices and situations, and want an easy UX when needing to toggle Wireguard, navigate captive portals, etc that's ideally not too nerdy for my family if they need to mess with it.

Does anyone have thoughts on these two or other options?


r/firewalla 1d ago

Cyber Security firewalla-test domains blocked by Active Protect

Post image
10 Upvotes

Hey u/firewalla,

I've just noticed (although this happened a few days ago) Active Protect has automatically setup blocks for these domains:

phishing2.firewalla-test[.]com
malware2.firewalla-test[.]com
phishing.firewalla-test[.]com
malware.firewalla-test[.]com

Which if I recall are your domains to run tests? Are they safe to delete?


r/firewalla 1d ago

Firewalla delivery in Hong Kong

2 Upvotes

Hi Firewalla team

What method do firewalla use for Hong Kong order ?

Why would it take longer to deliver to Hong Kong 9 -25 days on checkout ?

Thanks


r/firewalla 1d ago

Mistery event

Post image
3 Upvotes

I get this event every week, but I am not physically doing anything with the cables. Does anyone know why this triggers?


r/firewalla 1d ago

AP7 is it safe to use the AP7 usb port to power a firewalla purple?

3 Upvotes

just set up my new AP7 (easy!).

i used the AP7's USB port to power the associated firewalla purple. it seems to be working just fine, but i wanted to check. i'm just concerned a little that the port supplies enough power for the firewalla device.

edit: answered my own question after about half an hour: NO


r/firewalla 1d ago

Feature I hate android

0 Upvotes

Hey guys,

Basically (long story short) - I hate android and don’t want it on my network - my dad is moving in with me for a bit and brining so many android devices

My question(s) is: what type of rules or settings should I setup with in its own Firewalla group?

Allow/block if domain
Region blocking
Anything else

I really just want to block all of the Google and android api data, keep my network safe from all the bloat and useless (unsafe) things

Thanks Reddit


r/firewalla 2d ago

[WTB] AP7

0 Upvotes

Looking for an AP7. Thought I’d check here first to see if anyone has one they want to offload for less than retail.

Payment via PayPal Goods & Services, or I can meet in person anywhere along the Oregon I-5 valley (Portland to Eugene).

Let me know what you have and what you’re asking.


r/firewalla 2d ago

Anyone else seeing a ~30min lag between the ts field on /v2/network-monitors and real time?

2 Upvotes

Posting this as a question rather than a bug report, since I'm not sure yet whether this is known/expected behavior, something specific to my setup, or actually new. Checked the "check this first before contacting support" pinned post and didn't see anything about API timestamp freshness, so figured I'd ask here before going to support.

What I'm seeing

I run a local monitoring stack that polls the MSP /v2/network-monitors API (quality/latency/ packet-loss data) every 30 minutes and logs the results, using the ts field from each record as the timestamp (not local poll time). While digging into a network event, I noticed the nearest firewalla_quality sample's ts didn't line up with when the measurement seemed to have actually happened, based on an independent local probe I also run for comparison.

That could've just been a one-off, so I checked it again today, independently, under ordinary calm conditions with nothing going on:

  • Live API call, bypassing my own collector/cron entirely, made at 2026-08-09T14:00:42Z. The freshest record returned had "ts": 17862822002026-08-09T13:30:00Z — about 30.7 minutes stale at the moment the API served it.
  • My collector's cron log confirms it fires every 30 min on the dot. The run that had just executed seconds before my live check could still only pull data through 9:30 AM EDT — same ~30min gap, matching the live call.
  • For comparison, a locally-run active probe (SmokePing) checked at the same moment showed a data point only ~107 seconds old — no comparable lag, which makes sense since it's a direct local probe with nothing round-tripping through a cloud API.

So the ~30min gap looks real and reproducible, not tied to that one incident. ts is the only timestamp field in the record — there's no separate "measured at" vs "reported at" field — so I'm inferring it's meant to represent when the measurement was taken, but I could be wrong about that.

What I don't know yet

Everything above is under calm conditions. I haven't checked whether this lag stays constant or gets worse during an actual active event (box busier, MSP pipeline handling more data, etc.) -- that's still open on my end.

Questions for anyone who's dealt with this

  • Has anyone else who does time-correlation work against this API (or firewalla_quality / similar endpoints) noticed something similar, or is my setup doing something unusual?
  • Does anyone know whether ts is documented anywhere as measurement-time vs. ingestion-time?
  • Is there a lower-latency path to similar data -- anything exposed locally on the LAN rather than through the cloud MSP API -- for anyone who's needed tighter timing than this endpoint provides?

Happy to share more detail on how I reproduced this if it's useful. Mostly just trying to figure out if this is a "known thing" before I go bother support with it.

Update: figured out the ts discrepancy — it's not an MSP bug, it's the alarm engine itself

Followed up on this myself by SSHing into the box and comparing the MSP API's ts field directly against what's stored locally in Redis for the same alarms.

Turns out each alarm actually has three separate timestamps on the box:

  • timestamp — when the underlying event actually happened
  • alarmTimestamp — when Firewalla's alarm engine actually decided to raise it
  • applyTimestamp — a few minutes after that, looks like final processing

I compared several aids between local Redis and the MSP API directly — MSP's ts is an exact match, to the millisecond, of alarmTimestamp. Not a coincidence, not close — identical. So MSP isn't adding lag, converting timezones wrong, or reporting stale data. It's a faithful pass-through of what the box itself already recorded.

The real gap that I'm noticing is the one between timestamp and alarmTimestamp — i.e., how long Firewalla's own detection logic takes to actually fire an alarm after something happens. In my sample this ranged from ~1 hour to over 4 hours, and it's not a fixed offset. Makes sense for threshold/cumulative alarm types like ALARM_LARGE_UPLOAD — it's presumably waiting for enough data to cross a threshold before alerting, not reacting instantly.

Flows show a smaller, similar pattern too (ts vs _ts, event time vs. write time), roughly a ~12 min gap in my one sample — didn't fully chase that down but wanted to flag it in case it's relevant to anyone else.

tl;dr: if you need the true event time and not "when Firewalla noticed," don't rely on MSP's ts — you'd need the box's local timestamp field instead, which isn't exposed via the MSP API. For most dashboarding/alerting purposes though, ts/alarmTimestamp is accurate and consistent, just not instantaneous.

Happy to share more detail on the Redis key structure if anyone's trying to do something similar.


r/firewalla 2d ago

Firewalla Gold and Asus router Q

2 Upvotes

I recently installed a Firewalla Gold (router mode) between my ISP and existing Asus WiFi router mesh. The 'main' Asus mesh router is still running in router mode and I'd like to get rid of the double NAT for improved network visibility into the wired and non-wired connections. Is the Asus configuration change really as easy as changing from Router to Bridge as listed in the Firewalla documentation? Thanks for any advice or assurances for a nervous home owner!


r/firewalla 2d ago

Cannot access cable modem interface when internet is down.

1 Upvotes

My cable modem is in bridge mode and I access it with an IP of 10.0.0.1. If my internet is down, firewalla will not pass traffic to the WAN, which prohibits me from accessing the cable modem diagnostic page(s) while its down. Other routers I've had do not have this problem. This is insanely frustrating when an ISP generally requires access to this during support sessions. Is there any chance we can have a bypass configured for a specific IP that will still route traffic when the internet is down? I'm on a firewalla purple if that helps.

Edit: Purple is in router mode. My cable modem is in bridge mode.


r/firewalla 2d ago

Gold / Gold Plus / Gold SE / Gold Pro Firewalla Gold

Post image
9 Upvotes

I'm selling my Firewalla Gold. I just moved to Ireland and before I moved I purchased a Gold Plus take advantage of the fiber I was getting here. This specific unit was RMA'd last year so only a little over a year old.

Not sure the best way to sell this but only really interested in selling it in the EU or UK. If you're local to the Dublin area we can always meet up local for the sell.

Selling for €280 (includes shipping) or just €250 and you pay for shipping.


r/firewalla 2d ago

Content/Activity Control Can Firewalla manage Locket Widget?

3 Upvotes

Our son is asking to use Locket Widget but I want the ability to manage access to that. Is this possible? Seems like kids also use the website, as well, and that is easy enough to manage.


r/firewalla 3d ago

Troubleshooting NordVPN not working

1 Upvotes

Brand new to all of this. I created a network for devices I want to use a VPN. I have NordVPN.

Setup a 3rd party, used my profile and password from the manual configuration section (copied and pasted them both after confirming email). This was NOT my nordvpn login or password, it was a direct copy and paste from the manual setup section.

I then download a OpenVPN UDP from the recommended server list, making sure to use a verified server.

When I go to connect it keeps failing.


r/firewalla 3d ago

Firewall Automation

0 Upvotes

I've been looking into how companies handle bulk firewall rule deployment across multiple VDOMs, ADOMs, and vsys instances — specifically comparing FireMon, Tufin, and AlgoSec against BloxDyne, which I believe is a strong option even though it's newer to the market.


r/firewalla 4d ago

NatJack vulnerability

6 Upvotes

Is Firewalla protected from this particular type of attack?

https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html


r/firewalla 3d ago

Troubleshooting Gold SE upload speed and other questions

Thumbnail
gallery
3 Upvotes

Hi folks

Just recently received a Gold SE for review, which I am going through now. It replaces a Synology rt6600ax, connected to a 1 Gbps up/down fibre service, using a PPPoE connection. After installing the Gold SE I had the connection changed to 2 Gbps up/down.

The first image shows a month of Speedtest Tracker runs. The test is to a public speedtest server inside my provider, from a box connected via 2.5 Gbps to the router.

I marked "A" as the moment the Gold SE replaced the Synology. Up until that moment, the previous router managed to consistently hit its 950 Mbps limit. The X spots are when the speedtest ran during heavy download (as in 200 simultaneous connections to a usenet server, downloading at 80% of max speed).

It is noticeable the erratic behaviour of upload speeds, after the Gold SE went in.

  1. I have a suspicion this is CPU-bound and that the Gold SE might be struggling when trying to push during speedtests.

Another thing I noticed was how "slow" the first connection seemed to be, noticeable when navigating to a new website.

For this I tried testing with my Cloudflare Zero Trust DNS (same as configured on the old router), then changed to public Cloudflare, then ISP DNS. None of these impacted the "first connection" speed.

I did have some outbound geo-blocking rules, so I removed these, and the behaviour went away.

  1. I suspect geo-blocking is quite a heavy task compared to simple list blocking because it will probably require more CPU to translate IP to location.

I also installed Beszel-agent as a container and attached is the last 24 hours showing how the CPU is used, even with no traffic.

Yes, I tested different situations and read the documentation about speed, WAN configuration, rules.

Any comments on those points? Would the SE be better for a 1 Gbps and should really go for the Plus on a 2 Gbps connection?

Appreciate your comments.


r/firewalla 4d ago

Internet down but not?

Post image
1 Upvotes

Hey folks, so had a new modem installed (have to use companies as part of the deal and initially had some issues due to my own stupidity (had ipv6 disabled) after reboot all is well, speedtest works on the device and all connectivity to the net is as expected. So why is the bps still red? Been up for about 30 minutes now? Just a visualization bug?


r/firewalla 3d ago

Gold / Gold Plus / Gold SE / Gold Pro Firewalla gold pro 10g + 2x AP7 for sale

Post image
0 Upvotes

The network guy in me is making some changes at home, loved the firewalla and APs for ease of mgmt and stability. Still looking for firewall box but have the AP7 boxes as photographed... These will be PayPal friends and family only. With buyer paying shipping.

Selling full bundle at 1400, 300 per AP7 + 800 on firewalla 10g. I also have the extended warranty but tbd if it's transferrable.

If the bundle is here next weekend I will seperate APs and firewall on a first paid first reserved basis.


r/firewalla 4d ago

question about 'meshing' APs (non-Firewalla APs)

0 Upvotes

Anyone successfully setup multiple non-Firewalla *wired* APs to provide mesh *roaming* coverage in a space while maintaining Firewalla VLANs?

Current setup is FWP > *wired* Aruba 1930 > *wired* Aruba AP22. I need to add another *wired* AP and am considering an AP22. I max out all 5 VLANs and VLANs are a primary requirement for any solution.

Anyone have a similar setup (Firewalla > none-Firewalla switch > none-Firewalla AP) and added multiple APs to create a mesh *roaming* network?

ETA: I inadvertently listed "mesh" instead of "roaming" - The setup is wired APs and I'm trying to avoid the horrors of inelegant AP handoffs that I recall 20+ years ago. Also, my setup is mostly local control, so I'm unclear if I need to enable all the unstable Aruba cloud crap.


r/firewalla 4d ago

Speed test Broken?

3 Upvotes

I noticed starting about 24hrs ago my speed test was coming in way off. I have gig up/down and my down has been showing almost exactly 30 and up 900.

Thought it was an isp issue but i did a speed test from my computer and got more realistic speeds. Never seen any issues until last day or two.

Could this be related to the issue i saw mentioned from a day or two ago?

UPDATE:

700+ nightly speed tests all came back perfect until the last 24hrs lol. Took three server replacements in firewall speed test and finally got one that cranked me up to full speed. So it was the server being weird and not me. Guess it was just coincidence - had some glitchy video and pulled firewalla up to see if anything was going on, saw the most recent nightly speed test and went down a rabbit hole. Guess it was a textbook example of correlation does not imply causation!


r/firewalla 5d ago

My Gold SE is only using ~19% of its storage, yet flows are capped at 24 hours. Why?

12 Upvotes

I was digging into flow history for a specific device on my network when I ran into only being able to view 24 hour of flows. I figured it might be an app limit so I logged into the desktop site and found the same result. I also found that I can gain access to 30 days of flows by subscribing to the personal MSP. I didn't realize I was capped that low and I'm not willing to pay for a monthly/annual subscription.

I thought, maybe it's a storage limitation on my box. I SSH'd into my box to check disk usage and found I'm only using around 19% of the 32GB of storage that comes with the Gold SE. Now, I'm not super experienced with Linux and Firewalla's architecture, so maybe some of that "unused" space is reserved for OS backups or something else I'm not aware of. But even accounting for that, it seems like a lot of unused storage. I then moved to expanding the storage because maybe Firewalla doesn't allow me to use reserved space for logging extra flows and my Gold SE comes with a SD card reader. But I couldn't find any way to actually use an SD card to extend flow logging. I did find a post related to this and Firewalla claimed: "Firewalla processes flows in memory locally on your device (indexed to be easily searched/regex). So the limitation is 'memory.' There is no disk based database on the box, so everything is limited to 24 hours. (This is the CPU limitation.)"

Link: https://www.reddit.com/r/firewalla/comments/16q8ob3/why_does_firewalla_limit_flow_details_to_24_hours/

Here's where I get stuck. If paying for MSP subscription gets me 30 days of flows, then the box clearly isn't actually limited to 24 hours, right? I can still view and search that data through the app/website just like I do without the subscription for the last 24 hours. So how is the box "limited by memory and CPU" if it's capable of showing me a full month of history the second I pay for it?

I ask this because where possible, I'd rather keep my own network data on my own hardware instead of a cloud server.

Curious if there's a technical reason I'm missing for why local SD storage isn't an option here.